Threat Database Trojans Trojan.MSIL.Krypt.GEB

Trojan.MSIL.Krypt.GEB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,606
Threat Level: 80 % (High)
Infected Computers: 1,152
First Seen: January 3, 2013
Last Seen: July 6, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.GEB indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to infiltrate and damage computer systems, often without the user's knowledge or consent. It is essential to take immediate action to remove the threat and prevent further damage to your system and data.

What Is Trojan.MSIL.Krypt.GEB?

Trojan.MSIL.Krypt.GEB is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan.MSIL.Krypt.GEB" suggests that it may be related to encryption or cryptography, but without further information, it is difficult to determine its specific characteristics or behaviors. Trojan horses often exploit vulnerabilities in software or operating systems to gain unauthorized access to a system, where they can cause a range of problems, from stealing sensitive information to disrupting system performance.

How Trojan.MSIL.Krypt.GEB Operates

Like other Trojan horses, Trojan.MSIL.Krypt.GEB likely operates by exploiting weaknesses in system security or deceiving users into installing it. Once installed, it may communicate with its creators or other malicious programs to receive instructions or transmit stolen data. Trojan horses can also create backdoors, allowing hackers to access the system remotely and perform various malicious activities. The exact mechanisms used by Trojan.MSIL.Krypt.GEB are unknown, but it is clear that it poses a significant threat to system security and integrity.

Symptoms of Infection

Systems infected with Trojan.MSIL.Krypt.GEB may exhibit a range of symptoms, including slow performance, frequent crashes, or unusual network activity. Users may also notice unfamiliar programs or icons on their system, or receive unexpected messages or alerts. In some cases, the infection may not produce any noticeable symptoms, making it difficult to detect without the use of specialized security software. If you suspect that your system has been infected with Trojan.MSIL.Krypt.GEB, it is crucial to take immediate action to remove the threat and prevent further damage.

How to Remove Trojan.MSIL.Krypt.GEB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious programs or files.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

The removal of Trojan.MSIL.Krypt.GEB requires careful attention to detail and a thorough understanding of system security. By following the steps outlined above and using reputable security software, you can help to protect your system and data from this and other malicious threats. Remember to always be cautious when installing new software or clicking on links from unknown sources, and to keep your operating system and security software up to date to prevent future infections. With the right tools and knowledge, you can help to keep your system safe and secure.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GEB
Signature status: No Signature

Known Samples

MD5: 77a2d69f73888e7488561a37cf015aab
SHA1: 15ad113b51a38f1b2992f059c54f024576b4ee99
SHA256: F28CC710F6E172666962FFEE386CD50EE1C6C72A443196169C5C49942BE246AC
File Size: 1.44 MB, 1444848 bytes
MD5: d7d95ff408557557abe1f2a105032d16
SHA1: b7821ebc96fe912979a6ec2aaaa9b22a57065f0b
SHA256: 2BB0788FCA447F84B4D0ACB4D33762F185C974DC4455940B4F2CB890630A1413
File Size: 780.80 KB, 780800 bytes
MD5: 2cca38bce58e904282b2237bae1c4549
SHA1: 1410b15e49836200fce283e4aa32680c4655f561
SHA256: 56886F3D393781D750846A0C623B492435BB7CC5DA29242318C7CCDE87D93F44
File Size: 624.13 KB, 624128 bytes
MD5: 579232ceb4ad133378a7a2bad23a80e9
SHA1: 129bf9fd98f295cec4396aac8dae68c58fb57157
SHA256: 583E850F8350430E70C729BB7C566CD36C9BF50D5574FA66C6D34D3E08E76DEF
File Size: 1.27 MB, 1270784 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 14.0.0.0
  • 9.0.0.0
  • 2.5.5.0
  • 1.0.0.0
Comments
  • Aplikasi pembayaran non tunai bagi siswa dan pegawai di sekolah
  • HRID Shells Manipulator Control
  • Kehadiran Siswa dan Pegawai menggunakan Identifikasi Wajah
  • PerfPRO Studio Video Player
Company Name
  • Hartware Technologies
  • HRID-NDT Ltd.
  • PT. Performa Integrasi Teknologi Edukasi
File Description
  • HRID Shells Manipulator Control
  • JIBAS Face Server
  • JIBAS SchoolPay Secure Server - Cashless Payment
  • PPSVideo
File Version
  • 14.0.0.0
  • 9.0.0.0
  • 2.5.5
  • 1.0.0.0
Internal Name
  • FaceServer.exe
  • HRID Shells Manipulator Control.exe
  • PPSVideo.exe
  • SPayServer.exe
Legal Copyright
  • 2013 - 2021
  • Copyright © 2020, 2024
  • Copyright © JIBAS 2009
  • Copyright © JIBAS 2024
Legal Trademarks HRID-NDT Ltd., Zagreb - Croatia
Original Filename
  • FaceServer.exe
  • HRID Shells Manipulator Control.exe
  • PPSVideo.exe
  • SPayServer.exe
Product Name
  • HRID Shells Manipulator Control
  • JIBAS SchoolPay Secure Server - Cashless Payment
  • JIBAS Sistem Presensi Terpadu Face & Fingerprint
  • PerfPRO Studio
Product Version
  • 14.0.0.0
  • 9.0.0.0
  • 2.5.5
  • 1.0.0.0

Digital Signatures

Signer Root Status
Vision Quest Virtual LLC SSL.com EV Code Signing Intermediate CA RSA R3 Self Signed

File Traits

  • .NET
  • HighEntropy
  • msil.krypt
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 664
Potentially Malicious Blocks: 4
Whitelisted Blocks: 329
Unknown Blocks: 331

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? x ? ? ? ? ? ? x ? ? ? ? ? ? x ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? x 0 0 ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 ? 0 ? ? ? 0 0 0 ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? 0 ? ? 0 0 ? ? 0 ? 0 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? ? 0 ? ? ? 0 0 0 0 ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...