Malware

How to remove “MSIL/Kryptik.AARG”?

Malware Removal

The MSIL/Kryptik.AARG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AARG virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.AARG?


File Info:

crc32: 0BC347E8
md5: 4b87651766b45ec78c2c9ea9a6951e5c
name: 4B87651766B45EC78C2C9EA9A6951E5C.mlw
sha1: 6fd91fe21ba350f55bd6f00d389986084d4e3852
sha256: 6993ffac6e8c4020e152ce6ba165cf3efb429908340d2d9c02812dffc019cf0a
sha512: f4e642008a9af3a91b55727636c0155dde65db1d811c776fd2ad7548ae18a52c5642ae6cfab04b9903bd642a10090ea27fe516bd94ddd9fed8af7b5b09c0fb46
ssdeep: 1536:IPhkgRIPwByVczClLCrbkkIvNNnoDPjXQWjbizyiz+GyrPFjlpwP3E9vjWjOOsm:EmhmlPQ529Tg5S1111PR6s1j
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: WABMIG.EXE
FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.19041.1
FileDescription: Microsoft (R) Contacts Import Tool
OriginalFilename: WABMIG.EXE
Translation: 0x0409 0x04b0

MSIL/Kryptik.AARG also known as:

K7AntiVirusTrojan ( 0057ba341 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.12987
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.74864
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:MSIL/Kryptik.bc6339b3
K7GWTrojan ( 0057ba341 )
Cybereasonmalicious.766b45
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AARG
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
BitDefenderTrojan.GenericKDZ.74864
NANO-AntivirusTrojan.Win32.Remcos.iuqibh
MicroWorld-eScanTrojan.GenericKDZ.74864
Ad-AwareTrojan.GenericKDZ.74864
SophosMal/Generic-S
ComodoMalware@#3g37p3uu3hutg
BitDefenderThetaGen:NN.ZemsilF.34686.1n0@a8ZM5yci
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tz
FireEyeGeneric.mg.4b87651766b45ec7
EmsisoftTrojan.GenericKDZ.74864 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Dropper.Gen
AviraTR/AD.Remcos.lwkfq
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
AegisLabTrojan.Win32.Barys.4!c
GDataTrojan.GenericKDZ.74864
AhnLab-V3Trojan/Win.Remcos.R418486
McAfeeGenericRXOK-CS!4B87651766B4
MAXmalware (ai score=99)
MalwarebytesTrojan.PCrypt.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R06CH09DT21
RisingBackdoor.Remcos!8.B89E (CLOUD)
IkarusTrojan.MSIL.Krypt
FortinetMSIL/GenKryptik.FERF!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/Kryptik.AARG?

MSIL/Kryptik.AARG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment