Threat Database Trojans Trojan.MSIL.Krypt.DAGJ

Trojan.MSIL.Krypt.DAGJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,572
Threat Level: 80 % (High)
Infected Computers: 763
First Seen: September 14, 2022
Last Seen: July 23, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.DAGJ on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive overview of the threat, its characteristics, and the steps you can take to remove it from your system.

What Is Trojan.MSIL.Krypt.DAGJ?

Trojan.MSIL.Krypt.DAGJ is a type of malicious software, commonly referred to as a Trojan, that can compromise the security and integrity of your system. The name suggests that it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the .NET Common Intermediate Language (CIL). The "Krypt" part of the name may indicate that the malware has some form of encryption or obfuscation capabilities. However, without further analysis, the exact nature and capabilities of this specific threat cannot be determined.

How Trojan.MSIL.Krypt.DAGJ Operates

Trojans, in general, are designed to allow unauthorized access to a system, often for malicious purposes such as data theft, espionage, or the distribution of additional malware. They can operate in various ways, including but not limited to, creating backdoors, downloading and executing additional malware, or modifying system settings to compromise security. The specific operational details of Trojan.MSIL.Krypt.DAGJ would depend on its design and the intentions of its creators, which can vary widely among different types of malware.

Symptoms of Infection

Systems infected with Trojan.MSIL.Krypt.DAGJ may exhibit a range of symptoms, although some infections may remain asymptomatic until they are discovered through security scans. Common indicators of a Trojan infection include unusual system behavior, such as unexpected crashes, slow performance, or the appearance of unwanted programs or windows. Additionally, changes in browser settings, unexpected pop-ups, or the detection of unauthorized network activity could also signal the presence of malware.

How to Remove Trojan.MSIL.Krypt.DAGJ

  1. Boot your system into Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the malware.
  3. Uninstall any suspicious programs that were installed around the time the malware was detected, as these could be related to the infection.
  4. Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure that all components of the malware have been removed.

Conclusion

The removal of Trojan.MSIL.Krypt.DAGJ requires careful and thorough action to ensure that all components of the malware are eliminated from your system. It is crucial to use reputable security software and follow best practices for malware removal to prevent reinfection and protect your personal data. Regularly updating your operating system, applications, and security software, as well as practicing safe computing habits, such as avoiding suspicious downloads and links, are key to preventing future infections. If you are unsure about any part of the removal process, consider consulting with a security professional to ensure your system is fully secured.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.DAGJ
Signature status: No Signature

Known Samples

MD5: e9047bb72a0ce2fb12e30931d4c9778b
SHA1: 682b0debb5afd8cec3fa6359f39c638d7dcd8fe3
File Size: 1.82 MB, 1815552 bytes
MD5: 1a32d6541c7cc81c4d4f04fc14bba832
SHA1: e54847129ba1ec29fb86ec9ae53c20d92ba8e9ac
SHA256: 5F563EFA3660947A59B12AB8DECAB167EBF4B7C3ADA9939E253AD1256CFAFEB2
File Size: 829.44 KB, 829440 bytes
MD5: 917809bce1896390c0bba246ff481c48
SHA1: 53e74f8311ee2f78e0b26e2fbb6f7cf9f3e9b350
SHA256: 17938E0C5438006FD9BFCE2291F11545619F00D4EF459D6C851E419C321D61F4
File Size: 1.82 MB, 1815552 bytes
MD5: 80b54fbeaccf1f1aeb131c56bf3b42c1
SHA1: ea158854465633fe3594f0fb786fd6f8313ad55b
SHA256: EFAB45E445F7F3895AE26F54819EB30E7FDBE0B289E12D8F7C077F895EFBE2D4
File Size: 1.51 MB, 1511936 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 20.5.0.0
  • 1.0.0.0
Comments
  • Protection Agent
  • RC7 Remake
  • Win 10 Tweaker
Company Name
  • Team Anti Hyperion
  • Unknown Company Ltd.
  • XpucT
File Description
  • Protection Agent
  • RC7 Remake
  • Win 10 Tweaker
File Version
  • 20.5
  • 1.0.0.0
Internal Name
  • Protection Agent.exe
  • RC7.exe
  • Win 10 Tweaker.exe
Legal Copyright
  • Copyright © 2024
  • Copyright © 2026 EZIKALEXANDR
  • Copyright © XpucT
Legal Trademarks
  • EZIKALEXANDR
  • XpucT
Original Filename
  • Protection Agent.exe
  • RC7.exe
  • Win 10 Tweaker.exe
Product Name
  • RC7
  • Unknown Enterprise
  • Win 10 Tweaker
Product Version
  • 20.5
  • 1.0.0.0

File Traits

  • .NET
  • 00 section
  • 2+ executable sections
  • Confuser
  • HighEntropy
  • x64
  • x86

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent