Threat Database Trojans Trojan.MSIL.Krypt.EEJ

Trojan.MSIL.Krypt.EEJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,278
Threat Level: 80 % (High)
Infected Computers: 1,350
First Seen: July 10, 2021
Last Seen: June 15, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.EEJ on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and potentially steal sensitive information or disrupt system operations. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.MSIL.Krypt.EEJ?

Trojan.MSIL.Krypt.EEJ is a type of Trojan horse malware that can infect your computer through various means, such as malicious downloads, infected software, or exploited vulnerabilities. The name "Trojan" refers to the fact that this type of malware disguises itself as legitimate software, allowing it to bypass security measures and gain unauthorized access to your system. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic bytecode that can run on any Windows system.

How Trojan.MSIL.Krypt.EEJ Operates

Once installed, Trojan.MSIL.Krypt.EEJ can operate in various ways, depending on its intended purpose. It may attempt to connect to a command and control server to receive instructions from its creators, or it may start scanning your system for sensitive information, such as login credentials, credit card numbers, or other personal data. In some cases, the malware may also install additional components, such as keyloggers or ransomware, to further compromise your system.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Krypt.EEJ infection can vary, but common indicators include slowed system performance, unusual network activity, and unexpected changes to your system settings. You may also notice that your browser is being redirected to unfamiliar websites, or that your antivirus software is disabled or malfunctioning. In some cases, the malware may not exhibit any noticeable symptoms at all, making it difficult to detect without proper scanning tools.

How to Remove Trojan.MSIL.Krypt.EEJ

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or software that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and run another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Krypt.EEJ from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable security software, you can effectively remove the malware and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your system, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or links. By taking these precautions, you can help ensure the security and integrity of your computer and sensitive information.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.EEJ
Signature status: No Signature

Known Samples

MD5: 74e448ae0c04e3f1df9075abe8ef403a
SHA1: b9e299533ea2c8eabdeea8858e6df5d035756211
SHA256: 19D4C958991EA11D9E0A4DEBBFC4578EE8BA5CF02B81426E75D34709553004A9
File Size: 1.02 MB, 1017304 bytes
MD5: f03d82b56be73d63d3dec0c69343e2e9
SHA1: 3092eba549fe82f1748054215bae340c868085f1
SHA256: EE0E422B28923E4C51539365EEB79A348A4F8E72027F9EC660F85165E3EC1160
File Size: 1.51 MB, 1506816 bytes
MD5: 8ecbe9a790982849ac2872e07c426df1
SHA1: 72171a5e8e1666217508dfbf75ebaae45996a206
SHA256: 9519BA89713B01BEEBC3DB81DB26DA0954536FDC214D12CB53D45BFC0294BC53
File Size: 1.46 MB, 1457664 bytes
MD5: 5134babaefa617b197b29c9f3d0b6bc5
SHA1: 9d806b6c128be6ff8a2381d53a3f98571dfcef50
SHA256: C9D810C85CC68EDBF36D474FA4E492E2D85DB4F71D597B0E3FC16CCE3200B4FA
File Size: 1.16 MB, 1163776 bytes
MD5: e6dbce900c070b0ba660818f82f8d39e
SHA1: 0f436aed8b01c7ec7c2e3d8eb62505c29f0f4402
SHA256: D47271A872283F6B74A78375074BA3163F5A450AFFD71F7200549C6B36A2CE82
File Size: 230.91 KB, 230912 bytes
Show More
MD5: 7935bd6ab2f2c8622e3c82395b31cac7
SHA1: 7ade7bafbf6aa06f01c160066cf195acee546d87
SHA256: C42EFA864B1EEA668112766E6F54267B4D3A053700829FAA7AA362645BBF709E
File Size: 135.68 KB, 135680 bytes
MD5: 5f16e1b5c90d3605da498ff053acd407
SHA1: fc87be7d455f257dde265929a807460496117561
SHA256: 477C6F75B9C3A9A412C9E1D4439A0C5ECAC2F07A7C9C17935ED375836CBACC6E
File Size: 1.69 MB, 1688064 bytes
MD5: d846fdf87048f3b8293c934d31c92da9
SHA1: 531e209986562ad36f0bf5859e76c6f6c7447862
SHA256: 36BD43D054B8EBE03F4C9B975D6F4A5F2E255C640BEC3D0B4AD3305A1E9D5B0F
File Size: 1.64 MB, 1642496 bytes
MD5: 4c3c34580ad4929a033e8edea90e7fff
SHA1: 94fd8e71f4ea536d179ee4c5ab1fd7936f261608
SHA256: 863CE074809BEC793A775334A02FE081F1F873E31A8368E1E34193E3D5AA8D88
File Size: 854.02 KB, 854016 bytes
MD5: 82b622eaec04e1d52388933aa618211d
SHA1: 80c24d6f4479485de11d72c51e1cde9931d2b6ad
SHA256: 20967E123CCE990CB1B8FFA726332E4C5F81255F2AA1931F5286B98276BE2642
File Size: 854.02 KB, 854016 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.5.0.0
  • 1.0.1.17
  • 1.0.0.0
  • 0.0.9662.27779
  • 0.0.9659.14396
  • 0.0.0.0
Comments
  • LogiCAT 4.0 - Gestione Centri di Assistenza Tecnica
  • programa para comunicação via TEF com sistema de Controle Abastecimento
  • www.omnitek.com.br
Company Name
  • Expansiva Software
  • HP Inc.
  • LOGICA 2.0
  • OmniTek Tecnologia Ltda
  • Windows uE
File Description
  • BingoLotto
  • DCLAV - Contabilità Lavori
  • GHTRANSFERT
  • Latihan lks2
  • LogiCAT 4.0
  • OmniMark400
  • RedSur
  • Serman
  • TEF_Exp
File Version
  • 1.5.0.0
  • 1.00.01.17
  • 1.0.0.0
  • 0.0.9662.27779
  • 0.0.9659.14396
Internal Name
  • BingoLotto.exe
  • Gestione Contabilità Lavori.exe
  • GHTRANSFERT.exe
  • Latihan lks2.exe
  • LogiCAT 4.0.exe
  • OmniMark400.exe
  • RedSur.exe
  • Serman.exe
  • TEF_Exp.exe
Legal Copyright
  • c. 2015-2030 by OmniTek Ltd
  • Copyright © 2009
  • Copyright © 2013
  • Copyright © 2019
  • Copyright © 2022
  • Copyright © 2025
  • Copyright © HP Inc. 2024
  • Copyright © Windows uE 2013
Original Filename
  • BingoLotto.exe
  • Gestione Contabilità Lavori.exe
  • GHTRANSFERT.exe
  • Latihan lks2.exe
  • LogiCAT 4.0.exe
  • OmniMark400.exe
  • RedSur.exe
  • Serman.exe
  • TEF_Exp.exe
Product Name
  • BingoLotto
  • ContabLavori
  • GHTRANSFERT
  • Latihan lks2
  • LogiCAT 4.0
  • OmniMark400
  • RedSur
  • Serman
  • TEF Expansiva - Frotas
Product Version
  • 1.5.0.0
  • 1.00.01.17
  • 1.0.0.0
  • 0.0.9662.27779
  • 0.0.9659.14396

Digital Signatures

Signer Root Status
CPS\davide.cerasoli CPS\davide.cerasoli Self Signed

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • x86

Block Information

Total Blocks: 1,321
Potentially Malicious Blocks: 5
Whitelisted Blocks: 621
Unknown Blocks: 695

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 x 0 ? ? ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 ? 0 0 ? ? ? 0 0 ? 0 0 0 ? ? 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 0 0 ? 0 ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? 0 0 ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? x ? ? ? ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.MBDDI
  • MSIL.Krypt.YPB

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k�8��81��B�8 �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�-&�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃䬁耀꧌С> RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Keyboard Access
  • GetKeyState
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 840

Related Posts

Trending

Most Viewed

Loading...