Threat Database Trojans Trojan.MSIL.Krypt.JADA

Trojan.MSIL.Krypt.JADA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,640
Threat Level: 80 % (High)
Infected Computers: 24
First Seen: October 21, 2023
Last Seen: June 12, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.JADA on your system indicates a potential security threat that requires immediate attention. This malware is designed to compromise the security and integrity of your computer, and its presence can lead to a range of problems, from data theft to system instability. In this report, we will provide an overview of what Trojan.MSIL.Krypt.JADA is, how it operates, the symptoms of infection, and most importantly, the steps you can take to remove it from your system.

What Is Trojan.MSIL.Krypt.JADA?

Trojan.MSIL.Krypt.JADA is a type of malware that falls under the broader category of Trojans. Trojans are malicious programs that disguise themselves as legitimate software but are designed to allow unauthorized access to a computer system. The name Trojan.MSIL.Krypt.JADA suggests it may involve encryption or obfuscation techniques to evade detection and possibly to encrypt files on the victim's computer for ransom. However, without specific details, it's crucial to understand the general behavior of Trojans and the risks they pose, including data theft, spyware activities, and the potential to install additional malware.

How Trojan.MSIL.Krypt.JADA Operates

Malware like Trojan.MSIL.Krypt.JADA typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can communicate with its command and control servers to receive instructions, which might include stealing sensitive information, logging keystrokes, or using the infected computer as part of a botnet for malicious activities. The operating methods can vary widely, including but not limited to, spreading through phishing emails, infected software downloads, or exploited vulnerabilities in operating systems and applications.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Krypt.JADA infection can be subtle and may not always be immediately apparent. Common indicators of a Trojan infection include unexpected changes to computer settings, slow performance, frequent crashes, and unfamiliar programs or icons. Additionally, if the malware is designed to encrypt files, you might notice that your files are no longer accessible, and you may receive a ransom demand. It's also possible for a system to be infected without showing any obvious signs, making regular scanning with anti-malware tools crucial.

How to Remove Trojan.MSIL.Krypt.JADA

  1. Boot your computer in Safe Mode with Networking. This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the malware.
  3. Uninstall any programs that you do not recognize or that were installed around the time you suspect the infection occurred. Be cautious and only remove programs you are sure are not needed.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

The removal of Trojan.MSIL.Krypt.JADA requires careful and immediate action to prevent further damage to your system and to protect your personal data. By following the steps outlined above and maintaining good computer hygiene, such as regularly updating your operating system and applications, using strong antivirus software, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, prevention is key, but when infections do occur, acting quickly and effectively is crucial to minimizing harm.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.JADA
Signature status: No Signature

Known Samples

MD5: f32b07af3232e697871a82b5809e9f29
SHA1: 12c6895fd40181260077e60069e5b93def9baa65
SHA256: BCB0CDE1C99055BAB5F1948CA6884688DF13653EDD6B22AF15F85E2FE41670F3
File Size: 4.57 MB, 4568152 bytes
MD5: bd6af96dd51cae22f3724ee844d8594b
SHA1: 4d1d0dec7e370001b9c746124cfa27c4bb34e7cd
SHA256: 38CCFF995B666CA2B366271C6FC4194927FD6EADB220AD84DE9420F6C1F0AA1F
File Size: 545.28 KB, 545280 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.121.101
Comments A Relogger for Honorbuddy
Company Name YoYo Games Ltd.
File Description
  • ARelog
  • Installer for GameMaker Studio Remote Worker
File Version
  • 23.1.1.146
  • 1.0.121.101
Internal Name ARelog.exe
Legal Copyright (C) 2018 YoYo Games Ltd.
Original Filename ARelog.exe
Product Name
  • ARelog
  • GameMaker Studio Remote Worker
Product Version
  • 23.1.1.146
  • 1.0.121.101

Digital Signatures

Signer Root Status
YoYo Games Ltd. Symantec Class 3 SHA256 Code Signing CA Self Signed

File Traits

  • .NET
  • HighEntropy
  • RijndaelManaged
  • SmartAssembly
  • x86

Block Information

Total Blocks: 1,478
Potentially Malicious Blocks: 7
Whitelisted Blocks: 1,096
Unknown Blocks: 375

Visual Map

0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 0 0 ? ? 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? 0 0 ? ? ? ? 0 ? 0 0 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? x 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? ? ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? x 0 0 ? ? ? ? 0 ? 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 x ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\isolatedstorage\achoy5gw.frd\mrxe22t0.mvy\strongname.mettjqp1jj3mkpwzfnxc30xiyfyxtd45\assemfiles\e4daa5d5\d\ugxhdgzvcm06ic5orvqgnc4wigluc3rhbgxlza==.bin Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\isolatedstorage\achoy5gw.frd\mrxe22t0.mvy\strongname.mettjqp1jj3mkpwzfnxc30xiyfyxtd45\assemfiles\e4daa5d5\d\ugxhdgzvcm06ifdpbmrvd3mgoa==.bin Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\isolatedstorage\achoy5gw.frd\mrxe22t0.mvy\strongname.mettjqp1jj3mkpwzfnxc30xiyfyxtd45\assemfiles\e4daa5d5\d\ugxhdgzvcm0gq1bvienvcmvzoiay.bin Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\isolatedstorage\achoy5gw.frd\mrxe22t0.mvy\strongname.mettjqp1jj3mkpwzfnxc30xiyfyxtd45\assemfiles\e4daa5d5\d\ugxhdgzvcm0gq3vsdhvyzsboyw1loiblbi1vuw==.bin Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\isolatedstorage\achoy5gw.frd\mrxe22t0.mvy\strongname.mettjqp1jj3mkpwzfnxc30xiyfyxtd45\assemfiles\e4daa5d5\d\ugxhdgzvcm0gt1mgqml0bmvzczognjq=.bin Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\isolatedstorage\achoy5gw.frd\mrxe22t0.mvy\strongname.mettjqp1jj3mkpwzfnxc30xiyfyxtd45\assemfiles\e4daa5d5\usages.bin Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\isolatedstorage\achoy5gw.frd\mrxe22t0.mvy\strongname.mettjqp1jj3mkpwzfnxc30xiyfyxtd45\identity.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\isolatedstorage\achoy5gw.frd\mrxe22t0.mvy\strongname.mettjqp1jj3mkpwzfnxc30xiyfyxtd45\info.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsb9b3b.tmp\advsplash.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsb9b3b.tmp\modern-header.bmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsb9b3b.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\spltmp.bmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Keyboard Access
  • GetKeyState
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams

Related Posts

Trending

Most Viewed

Loading...