Threat Database Trojans Trojan.MSIL.Krypt.GBMD

Trojan.MSIL.Krypt.GBMD

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 114
First Seen: September 8, 2022
Last Seen: November 13, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.GBMD indicates that your system has been compromised by a potentially malicious program. This type of threat is generally categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. Trojans can have various functions, including data theft, system compromise, and malicious activity execution. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.MSIL.Krypt.GBMD?

Trojan.MSIL.Krypt.GBMD is a type of malware that can infect your system and perform various malicious activities. The name itself does not provide specific information about its functionality or origin, but it is clear that it is a potentially harmful program. Trojans like this one can be spread through various means, including infected software downloads, phishing emails, or exploited vulnerabilities in your system or applications.

How Trojan.MSIL.Krypt.GBMD Operates

Once installed, Trojan.MSIL.Krypt.GBMD can operate in different ways, depending on its intended purpose. It may attempt to connect to remote servers to receive instructions or send stolen data. Some Trojans can also install additional malware or create backdoors for future access. The exact operation of Trojan.MSIL.Krypt.GBMD is not specified, but it is crucial to remove it to prevent potential harm to your system and data.

Symptoms of Infection

Identifying a Trojan infection can be challenging, as these programs often disguise themselves as legitimate software. However, some common symptoms may indicate the presence of malware like Trojan.MSIL.Krypt.GBMD. These include slow system performance, unexpected pop-ups or ads, unfamiliar programs or icons, and suspicious network activity. If you notice any of these symptoms, it is essential to take immediate action to scan your system and remove any potential threats.

How to Remove Trojan.MSIL.Krypt.GBMD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access for updates and scans.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove Trojan.MSIL.Krypt.GBMD and any other potential threats.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the infection.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or settings that the Trojan may have altered.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.MSIL.Krypt.GBMD from your system is crucial to prevent potential data theft, system compromise, and other malicious activities. By following the steps outlined above and maintaining good cybersecurity practices, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, staying vigilant and proactive is key to protecting your digital assets and ensuring the security of your system.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GBMD
Signature status: No Signature

Known Samples

MD5: a382d9cf1f8fe735c146d02ccc272671
SHA1: d0ca76cb1a2e9564545e1714975c4231ab3f562e
SHA256: 8030C3AB5CE14C4F748F6C1953816249DA1496C3D2340A74B3AE73AE3FACFDDD
File Size: 182.27 KB, 182272 bytes
MD5: 3a28c063f214220da89bf06231dba1d5
SHA1: 154d8561460ae8744b939950ecd5e34e3aa004cf
SHA256: 230A8D0E7BEA5258FDD6BFEAC8188382C9AB7DFF317B305A220C88ECCF05783C
File Size: 258.56 KB, 258560 bytes
MD5: b912bd0c6f6619e0b716987a8816a19b
SHA1: 9e3e669843669ed0f08590ec78f99a38f07f6c8c
SHA256: 2DB8C22654EE38A934F01D594B4B4A0713E929B61C065E3D7BCFF65D57B7C7D4
File Size: 182.27 KB, 182272 bytes
MD5: 2357bea61ef046e3b400baaeaadeccfe
SHA1: e46d4bb4c8868d0503f1bbb4ffb295e3e649deeb
SHA256: 76DF3C5D5158B5FFD0A4AB908C0835100C253B9829665FD557F42FCB7A181534
File Size: 283.14 KB, 283136 bytes
MD5: 5d570abbb8d205a73207ad0d08dad108
SHA1: 89fc848b0e44deaaa7b0675b956dada7f784497a
SHA256: 9CC7906F4CEAF7983C7C5CFA4C1630A970E7CF5636F0F97862CB0160DE166AF0
File Size: 281.60 KB, 281600 bytes
Show More
MD5: 632b4ad98cffcf268d5d3185dd3e3767
SHA1: 918a604bdbcb2e5205d18faf8b72ab27e3a76feb
SHA256: 9EEEF52B0C045FFA5CE67EB211B1B8D35C289F0A8199C073821A515B0F629205
File Size: 283.14 KB, 283136 bytes
MD5: 310bec3716ce60dce56f8b3f8cb738ca
SHA1: 820a60f173aaebcea228f15869d75cfea745fa0d
SHA256: D235AFE80CF6C6DD763D8729DFC9F86AD477F6A70BCAD0C88E9AD23F343BD7E6
File Size: 283.65 KB, 283648 bytes
MD5: 8fae8cdcdb1c9b034e72a69490633558
SHA1: bc1180115f718abbd05b8073b3cb986fa69d26f9
SHA256: 93A27BF171FAC9AF8953C61E7DCE35ADB644B5111238A5DEE4A0E83D14DD3A78
File Size: 282.62 KB, 282624 bytes
MD5: 1aff30bcfd9df1cf8c9cf1544bf0af2a
SHA1: 04bf9063bae3903db90b22eeb4491ae250571642
SHA256: 49AC2898194384BAABB8978949782D4E0A92ADC90549D608E1284687E95539D6
File Size: 283.14 KB, 283136 bytes
MD5: a9dac93314f94c66bb22e5229cc567c3
SHA1: 5bbae9dad8a484c253085bb95630caa8ab5ca748
SHA256: 579B5A8134EB5CB03F5E36D34E00A8E65457CBEA4F0652FA366E5C741B94300B
File Size: 282.11 KB, 282112 bytes
MD5: 73a1886d13199f9bffb7a0983e3a7aae
SHA1: dccd1a952a0a0a8c480ce0352a3e225c5c7c11b9
SHA256: 75223291709D946EEC93716FEC9AAA365885D530FA3E01979543184199DF79C5
File Size: 283.65 KB, 283648 bytes
MD5: 9c1bec49b886b36b2a168d23b6b6ae86
SHA1: be6ea53414263bb48f96debe40a6a3324b841078
SHA256: 44835FF6C80DFC528974E66485DC555311F7B464D23B3CCA054BDEAA48B8EDDB
File Size: 283.14 KB, 283136 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name
  • HP
  • Microsoft Corporation
File Description
  • Krnl Remake
  • User OOBE Broker
File Version
  • 10.0.26100.3624 (WinBuild.160101.0800)
  • 1.0.0.0
Internal Name
  • Krnl Remake.exe
  • User OOBE Broker
Legal Copyright
  • Copyright © HP 2025
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • Krnl Remake.exe
  • UserOOBEBroker.exe
Product Name
  • Krnl Remake
  • Microsoft® Windows® Operating System
Product Version
  • 10.0.26100.3624
  • 1.0.0.0

File Traits

  • .NET
  • Confuser
  • x64
  • x86

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...