Threat Database Trojans Trojan.MSIL.Krypt.EED

Trojan.MSIL.Krypt.EED

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,296
Threat Level: 80 % (High)
Infected Computers: 217
First Seen: April 16, 2021
Last Seen: July 17, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.EED on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with information on what this threat is, how it operates, its symptoms, and most importantly, how to remove it from your computer to prevent further damage.

What Is Trojan.MSIL.Krypt.EED?

Trojan.MSIL.Krypt.EED is identified as a Trojan-type threat. Trojans are malicious programs that can cause significant harm to your computer system. They are designed to allow unauthorized access to the victim's system, potentially leading to the theft of sensitive information, disruption of system operation, or exploitation of the system's resources for malicious activities. The name Trojan.MSIL.Krypt.EED itself does not directly indicate a specific malware family but suggests it is a type of Trojan written in MSIL (Microsoft Intermediate Language) with possible encryption or obfuscation features (indicated by "Krypt").

How Trojan.MSIL.Krypt.EED Operates

Trojan.MSIL.Krypt.EED, like other Trojans, operates by disguising itself as a legitimate program or file to trick users into installing it on their systems. Once installed, it can execute a variety of malicious actions, including but not limited to, stealing personal data, installing additional malware, providing backdoor access to hackers, or disrupting system operations. The specific operations of Trojan.MSIL.Krypt.EED can vary, but its primary goal is to compromise the security and integrity of the infected system.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow system performance, unfamiliar programs or icons, and changes in system settings. Additionally, you might notice increased network activity without a clear cause, or your antivirus software may detect and alert you to suspicious activity. It's crucial to be vigilant and monitor your system for any unusual behavior that could indicate the presence of malware like Trojan.MSIL.Krypt.EED.

How to Remove Trojan.MSIL.Krypt.EED

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for a safer removal process.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove all traces of the malware.
  3. Uninstall any recently installed programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and perform another full scan with your antivirus software to ensure that all malware components have been removed.

Removing Trojan.MSIL.Krypt.EED requires careful and thorough action to ensure that all components of the malware are eliminated from your system. It's also a good practice to regularly update your operating system, browsers, and antivirus software to protect against future threats.

Conclusion

The detection and removal of Trojan.MSIL.Krypt.EED are critical steps in protecting your computer and personal data from malicious activities. By understanding what this threat is, how it operates, and how to remove it, you can take proactive measures to secure your system and prevent future infections. Regular system maintenance, including updates and scans, along with cautious internet browsing habits, are key to maintaining a secure computing environment. If you are unsure about any part of the removal process, consider consulting with a cybersecurity professional to ensure your system is thoroughly cleaned and protected.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.EED
Signature status: No Signature

Known Samples

MD5: 4413037860c23f1ce8c02e2a6095ffac
SHA1: f827a1150e0dba53788f5a92714c43df22eb9ff7
SHA256: 5FC3242B841C3A415F31E5B9B2C99F499726823BB928188A827A94B9C66495A6
File Size: 283.65 KB, 283648 bytes
MD5: 4929b82b0605184c520e2e9c053daf67
SHA1: 90c2d94263411ddbfa5727002789df5e219b5029
SHA256: 072F8360CBF07A335F1A280CA605FEB355A8C10CEDFBAE4ED494C8B4BE269BBB
File Size: 71.17 KB, 71168 bytes
MD5: 7ed651cb29a14b5d321108bba753d74a
SHA1: cc7313011fab7d77c6f728503bda691126405c47
SHA256: C66CE7A449321A0E50DAFD5FCD1CC740D92BD9D682C2C69CAC070D9A9008753C
File Size: 71.17 KB, 71168 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Prueba-01
File Description
  • Prueba-01
  • ST
File Version 1.0.0.0
Internal Name
  • Prueba-01.dll
  • ST.exe
Legal Copyright Copyright © 2014
Original Filename
  • Prueba-01.dll
  • ST.exe
Product Name
  • Prueba-01
  • ST
Product Version
  • 1.0.0.0
  • 1.0.0

File Traits

  • .NET
  • CryptUnprotectData
  • NewLateBinding
  • No CryptProtectData
  • ntdll
  • Run
  • x86

Block Information

Total Blocks: 80
Potentially Malicious Blocks: 9
Whitelisted Blocks: 66
Unknown Blocks: 5

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 x x x x 0 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Bulz.PPE
  • MSIL.Bulz.WC
  • MSIL.Bulz.WE
  • MSIL.Bulz.WF

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 680

Related Posts

Trending

Most Viewed

Loading...