Threat Database Trojans Trojan.MSIL.Krypt.MAD

Trojan.MSIL.Krypt.MAD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 4,849
Threat Level: 80 % (High)
Infected Computers: 17,098
First Seen: July 1, 2021
Last Seen: July 19, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.MAD indicates that a potentially malicious program has been identified on your system. This type of threat is generally categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. Trojans can have various functions, including data theft, system compromise, and malicious activity execution. It's essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is Trojan.MSIL.Krypt.MAD?

Trojan.MSIL.Krypt.MAD is a type of malware that can infiltrate your system through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. The name itself does not provide specific information about its functionality or origin, but it suggests that it may be related to data encryption or obfuscation. It's crucial to note that malware authors often use misleading or confusing names to evade detection and make removal more challenging.

How Trojan.MSIL.Krypt.MAD Operates

Once installed, Trojan.MSIL.Krypt.MAD can operate in the background, potentially without visible symptoms. It may communicate with command and control servers to receive updates, transmit stolen data, or execute malicious commands. The malware can also spread to other parts of the system, infecting files, and compromising system integrity. Understanding the operational methods of this malware is vital to developing an effective removal strategy.

Symptoms of Infection

Systems infected with Trojan.MSIL.Krypt.MAD may exhibit various symptoms, including slow system performance, frequent crashes, and unusual network activity. You may also notice unfamiliar programs or processes running in the background, or find that your system settings have been altered without your consent. However, some malware can operate without noticeable symptoms, making regular system scans and monitoring essential for early detection.

How to Remove Trojan.MSIL.Krypt.MAD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Perform a full system scan using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware. Ensure that the tool is updated with the latest definitions to improve detection accuracy.
  3. Uninstall any suspicious programs that were installed around the time of the infection. Be cautious when removing programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that the malware may have altered.
  5. Reboot your system and perform another full scan to ensure that all remnants of the malware have been removed. This step is crucial to verifying that the removal was successful and that your system is clean.

Conclusion

Removing Trojan.MSIL.Krypt.MAD requires a thorough approach to ensure that all components of the malware are eliminated. By following the steps outlined above and maintaining good system hygiene, you can reduce the risk of reinfection and protect your system from similar threats. Regular system scans, keeping software up-to-date, and being cautious when interacting with unknown sources are key practices in preventing malware infections. Remember, the detection and removal of malware are ongoing processes that require vigilance and the use of reputable security tools.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MAD
Signature status: No Signature

Known Samples

MD5: 32977c6bec4c531ebca58c052f60a92b
SHA1: 24a969d5dea0b13e2069cfcf0e8a7d3892700b2c
File Size: 1.57 MB, 1565184 bytes
MD5: 2c48576d595ef87d9ca1842b05044e5a
SHA1: 8dd5b7bdd42369c629edea40a6ab992ba5cfb3c2
SHA256: 7C2C4D36795AD943C7E33E1AB63820698497E78357AB606E3DFF27C3EF299A40
File Size: 1.40 MB, 1402368 bytes
MD5: 8190a9ad00741bb884a1e1141ea45c30
SHA1: 80cd18065341c6a1e461a93ca62d69dcfaafa31e
SHA256: C5192171930618F2BCC7CA6CC2761314368A31281A3B8A0D8A4457118A6ED08B
File Size: 517.63 KB, 517632 bytes
MD5: 4ca12f066ddf27c049f1e17c05a2fb77
SHA1: 2d4d7350c59f65f3a8c4ec58e3e8d6807b99c852
SHA256: C71B496D6DFF3B073CC3F81725A19DF26B31E65D7D675D79F8C4DD83E2CA4C2E
File Size: 1.63 MB, 1629184 bytes
MD5: ed983ed246ac613b278095bf546d3fad
SHA1: 44e725b06c102ec0d19e23121763f30a30cacf4f
SHA256: 3AC852E687D7C848B9534ABE7B11835C7C324F121614B70F84264B4E4751B438
File Size: 285.70 KB, 285696 bytes
Show More
MD5: f0f76810036cbabc7fcb81060ece6d66
SHA1: 8dc3c74988db94dbf60258171583cba1df2cd906
SHA256: 5D0BA70C44CE41CB5A4C88E51173016CBDFF2721D901758AAFC43484D27F4967
File Size: 168.45 KB, 168448 bytes
MD5: ea85b4837db12c1a0fbcda1af8844935
SHA1: 82fa7faca6bb51c7b076361a4cdfd997165c215b
SHA256: EA0C13E3C0351BA3DC665C484DD4282356AA4401414BEFC8E59431CBB30CA4CC
File Size: 1.46 MB, 1455616 bytes
MD5: a9a914ad24c08a2ad97af8d104d82953
SHA1: 32fb89a7cac411208e48903965bb80415cffa1d6
SHA256: 25290F26511126DD26B91C9DF13200DA2529BDF719AAB99019D1CB07336778BD
File Size: 1.46 MB, 1461248 bytes
MD5: 4c6afe3ff1ba770205065f43e8f45875
SHA1: 813296a048e162a80dcc5b74c1bd93e5a97bce92
SHA256: BB65D59DFFD0F7039E5D3B69432F9A0FCF41C57FFFED4CFF06A429B39E7B681C
File Size: 609.28 KB, 609280 bytes
MD5: ac79d0ee9ccb1f07b0d51ad38bb23205
SHA1: e1f14f4d0e3cda9391677e38f96d336a1316d03b
SHA256: 0540491F7949758B2E4EF50E7189EF01D01543EF40CFFC897DC09C26F36ED606
File Size: 1.40 MB, 1400832 bytes
MD5: 0b9ca2671c895f053aa38505c924452c
SHA1: c53b8a788bc316e3fe54546ccfc5a44c4893d9d7
SHA256: 309F8055A722F24798686AE9B28F00299DF8B087C5195AC752F220FCCC52D9C1
File Size: 379.90 KB, 379904 bytes
MD5: 6f25f2a052e9eb72967948877e14f108
SHA1: 4722b0e6666a58110b57be26993e5b60042d3b65
SHA256: C65722E8046EFF2ABA6AF3AFF578BB70D40D12D55EEBBDCB7365E7C977D0678B
File Size: 629.25 KB, 629248 bytes
MD5: 3200799fe620539e04eb59acc99afa96
SHA1: 49f4b8ab24ddca85b4ea1e4438c8f16ac3c2af25
SHA256: C3BFAB4BF62D249B7F316D6B70BD5750DF3A7A9C70421D08C733823D703E4AB2
File Size: 499.71 KB, 499712 bytes
MD5: 509a1f923465b35e3f9a99950bb108ba
SHA1: 566864ab8deadcf691928e58a6747758de973461
SHA256: E66054C8C04646B923DAFABD3D5C552F2DC67FDC6FE396A9748EC15550CC9442
File Size: 1.20 MB, 1196544 bytes
MD5: b1868321ed254e3fc0d062f742a7f81f
SHA1: be23ee40df5f1f69a083a360bb7ac2b475ff8e91
SHA256: 49632E2979845594BFB4D1756A411A565ECF32B8480558FD197F1DF7DF67C44E
File Size: 1.67 MB, 1672704 bytes
MD5: 91e79d21737feb5de45819e8fbe9c29c
SHA1: 6e9e5c96792e3c699b63b3cc46e1acdc132eefa1
SHA256: 9167327D8B16A3AAE2B9229CF0AF0029ECEF102DF369FCFEBAC4FE29F9316E18
File Size: 669.70 KB, 669696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Assembly Version
  • 5.53.2.6
  • 5.7.3.0
  • 2.51.225.19201
  • 2.6.0.1
  • 2.3.6.0
  • 1.11.0.0
  • 1.1.0.12
  • 1.0.0.2
  • 1.0.0.1
  • 1.0.0.0
Show More
  • 0.22.3.219
  • 0.1.3.0
Comments
  • A utility to view and analyze CSV data.
  • Check Tech Scan Tool Software
  • Gerenciador de backups do Situator.
  • HRID Chehli Manipulator Control
  • JTAlert Decodes History V3
Company Name
  • ATLIBITUM
  • Carrier Fire & Security
  • EasyMorph Inc.
  • HamApps by VK3AMA
  • HRID-NDT Ltd.
  • OTB Powersports
  • Seventh
  • SystemApiService
File Description
  • AnalysImmo Perform
  • Check Tech Software
  • CSViewer
  • Decodes History V3
  • EasyMorph Launcher
  • Gerenciador de Backups
  • Guerra Installer
  • HRID Chehli Manipulator Control
  • JanisonReplayService
  • Magic Installer
Show More
  • RemoteToolG24
  • RemotoSWClear
  • SystemApiService
  • TheMagicRemote
  • Titan Export Converter
  • VolumetricaBridge
File Version
  • 7.3.4.0
  • 5.53.2.6
  • 5.7.3.0
  • 2.51.225.19201
  • 2.6.0.1
  • 2.3.6
  • 1.11.0.138
  • 1.1.0.12
  • 1.0.0.2
  • 1.0.0.1
Show More
  • 1.0.0.0
  • 0.22.3.219
  • 0.1.3.0
Internal Name
  • AIP.exe
  • Check Tech Software.exe
  • CSViewer.exe
  • DecodesHistory.exe
  • Guerra Installer.exe
  • HRID Chehli Manipulator Control.exe
  • JanisonReplayService.exe
  • Magic Installer.exe
  • Morph.Launcher.exe
  • RemotoSWClear.exe
Show More
  • Seventh.Situator.Backup.exe
  • SystemApiService.dll
  • TheRemoteTool.exe
  • TheRemoteToolG24.exe
  • TitanExport.exe
  • VolumetricaBridge.exe
Legal Copyright
  • 2013 - 2022
  • Copyright ATLIBITUM © 2025
  • Copyright © 2015-2024 EasyMorph Inc.
  • Copyright © 2015-2025 EasyMorph Inc.
  • Copyright © 2018
  • Copyright © 2019
  • Copyright © 2019, Laurie VK3AMA
  • Copyright © 2021
  • Copyright © 2024
  • Copyright © FAmilia Guerra 2024
Show More
  • Copyright © Guerratool 2024
  • Copyright © Seventh 2014
  • Copyright © ThemagicTool 2024
  • © 2022 Carrier
Legal Trademarks
  • All Rights Reserved
  • EasyMorph
  • HRID-NDT Ltd., Zagreb - Croatia
Original Filename
  • AIP.exe
  • Check Tech Software.exe
  • CSViewer.exe
  • DecodesHistory.exe
  • Guerra Installer.exe
  • HRID Chehli Manipulator Control.exe
  • JanisonReplayService.exe
  • Magic Installer.exe
  • Morph.Launcher.exe
  • RemotoSWClear.exe
Show More
  • Seventh.Situator.Backup.exe
  • SystemApiService.dll
  • TheRemoteTool.exe
  • TheRemoteToolG24.exe
  • TitanExport.exe
  • VolumetricaBridge.exe
Product Name
  • ADN
  • ATS8550
  • Check Tech Software
  • CSViewer
  • Decodes History V3
  • EasyMorph Launcher
  • Guerra Installer
  • HRID Chehli Manipulator Control
  • JanisonReplayService
  • Magic Installer
Show More
  • RemoteToolG24
  • RemotoSWClear
  • Situator
  • SystemApiService
  • TheMagicRemote
  • VolumetricaBridge
Product Version
  • 7.3.4.0
  • 5.53.2.6
  • 5.7.3.0
  • 2.51.225.19201
  • 2.3.6
  • 1.11.0-bamboo+4e8a32c4
  • 1.1.0.12
  • 1.0.0.2
  • 1.0.0.1
  • 1.0.0+ce8292020fcff6e37fe6361baabfa8766fdebd42
Show More
  • 1.0.0
  • 0.22.3.219
  • 0.1.3

File Traits

  • .NET
  • HighEntropy
  • Installer Version
  • msil.krypt
  • NewLateBinding
  • ntdll
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 837
Potentially Malicious Blocks: 1
Whitelisted Blocks: 830
Unknown Blocks: 6

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.HGC
  • MSIL.Agent.JI
  • MSIL.Agent.XY
  • MSIL.CsdiMonetize.VQ
  • MSIL.CsdiMonetize.WB
Show More
  • MSIL.CsdiMonetize.WD
  • MSIL.Krypt.GEEVA

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\volumetrica trading::proxymode RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Keyboard Access
  • GetKeyState
Other Suspicious
  • AdjustTokenPrivileges

Related Posts

Trending

Most Viewed

Loading...