Malware

MSIL/Kryptik.AARM information

Malware Removal

The MSIL/Kryptik.AARM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AARM virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.AARM?


File Info:

crc32: B2B22560
md5: 116db2200d9be33529615fc98907d4d8
name: 116DB2200D9BE33529615FC98907D4D8.mlw
sha1: 29cf6588682aca66c59e41e0517ede00c75cc76d
sha256: 43bc7ada65633263e408152d7b117de464c9d23b2758d96a6822bde9ad27b170
sha512: b4d80a7769365e0975bf03add9f59a618e43fa85f12b1a04c40f428fc32bee65e14edb4fd38beb4dd71c5a588762670c0a2cd18452d790289532be342c5cbf7e
ssdeep: 12288:KYaTBJ1qtapo1SuoMwcQvFLJlCLL/HDtysCfO263+LS7EytLMsq9Sv:KYaT/1qt8oM9MK9PCYV6OmEcL9v
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: SeekOrigin.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: TechSupportRegistration
ProductVersion: 1.0.0.0
FileDescription: TechSupportRegistration
OriginalFilename: SeekOrigin.exe

MSIL/Kryptik.AARM also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36827929
MalwarebytesTrojan.Crypt
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/starter.ali1000139
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8682ac
CyrenW32/MSIL_Kryptik.AHX.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.AARM
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Taskun.gen
BitDefenderTrojan.GenericKD.36827929
ViRobotTrojan.Win32.Z.Taskun.724480
MicroWorld-eScanTrojan.GenericKD.36827929
TencentMsil.Trojan.Taskun.Dvqb
Ad-AwareTrojan.GenericKD.36827929
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.116db2200d9be335
EmsisoftTrojan.GenericKD.36827929 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Script/Phonzy.B!ml
AegisLabTrojan.MSIL.Taskun.4!c
GDataTrojan.GenericKD.36827929
AhnLab-V3Trojan/Win.Generic.C4447829
McAfeeArtemis!116DB2200D9B
MAXmalware (ai score=87)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CE121
RisingTrojan.Taskun!8.11327 (CLOUD)
YandexTrojan.AvsArher.bTJEKx
IkarusTrojan.MSIL.Agent
FortinetMSIL/Kryptik.AARH!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/Kryptik.AARM?

MSIL/Kryptik.AARM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment