Threat Database Trojans Trojan.MSIL.Krypt.MBR

Trojan.MSIL.Krypt.MBR

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,301
Threat Level: 80 % (High)
Infected Computers: 805
First Seen: July 10, 2021
Last Seen: June 9, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.MBR on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.MSIL.Krypt.MBR?

Trojan.MSIL.Krypt.MBR is a type of malicious software, or malware, that can compromise the security and integrity of your computer system. The name suggests it is a Trojan-type threat, which typically disguises itself as legitimate software to gain unauthorized access to a computer. Trojans can be used to spy on users, steal sensitive information, or disrupt system operation.

How Trojan.MSIL.Krypt.MBR Operates

Malware like Trojan.MSIL.Krypt.MBR operates by exploiting vulnerabilities in software or deceiving users into installing it. Once installed, it can perform a variety of malicious actions, including data theft, keystroke logging, or using the infected computer as part of a botnet for distributed denial-of-service (DDoS) attacks. The specifics of its operation can vary widely, but the end goal is typically to benefit the attacker at the expense of the user's privacy and system security.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Krypt.MBR infection can be subtle and may not always be immediately apparent. Common indicators include unusual system behavior, such as unexpected pop-ups, slow performance, or frequent crashes. You might also notice unfamiliar programs or toolbars in your browser, or find that your browser's homepage has been changed without your consent. In some cases, the malware may operate silently, making it difficult to detect without the aid of security software.

How to Remove Trojan.MSIL.Krypt.MBR

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and interfering with the removal process. To do this, restart your computer and press the key to access your boot menu (this key varies by manufacturer but is often F12, F2, or Del). Select the option to boot into Safe Mode with Networking.
  2. Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any other malware that may be present.
  3. Uninstall Suspicious Programs: Go through the list of installed programs on your computer and uninstall any that you do not recognize or that were installed around the time your system became infected.
  4. Reset Your Browser Settings: Malware often targets browsers, changing settings or installing unwanted extensions. Resetting Chrome, Firefox, Edge, or whatever browser you use can help remove these changes. Each browser has its own method for doing this, usually found in the settings or preferences menu.
  5. Reboot and Re-scan: After taking the above steps, reboot your computer and run another full scan with your anti-malware tool to ensure that all traces of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Krypt.MBR from your system requires careful and thorough action to ensure all components of the malware are eliminated. By following the steps outlined above and maintaining vigilance through regular system scans and safe browsing practices, you can help protect your computer and personal data from future threats. Remember, prevention is key: keeping your operating system, software, and security tools up to date, along with being cautious when downloading and installing programs, can significantly reduce the risk of infection.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MBR
Signature status: No Signature

Known Samples

MD5: c4461c10dceb7824a747ed231cf4a4fa
SHA1: 326cdc611cac1a0876d28a4fc9f6169859b306ff
SHA256: 95DD21FD44D209358B363BE9017E47A18F2879533D8A118151C365A4E1554855
File Size: 1.38 MB, 1380352 bytes
MD5: 57f51e4e9a0664509159fb4d1b5c90eb
SHA1: 5e9fb890695ba1c344f232eca246046b0173ebda
SHA256: 5FC00C4EBBEA3882C39107A632AE7875A6FB3E20B7C2208CC3CBF6F696D439D5
File Size: 1.86 MB, 1856512 bytes
MD5: 23e074b7f189fe5e146a53e58447f2f0
SHA1: 1ce17afa9ea9c2eaa5e258234194d218f82a9b69
SHA256: 651D6B4EBB8204FCB17A9621F6659167C0039C2E176BC95A31342ACA7BF6FADD
File Size: 1.95 MB, 1946112 bytes
MD5: 9457dc4a4bbe77fb169a7a95ae7dcbbd
SHA1: 6cf74e936ec229e22e139d4a8d522489a783c6c9
SHA256: C6A3688607DED69731282D35A217E096993000F400982A0BE611FD85A0B647F8
File Size: 151.04 KB, 151040 bytes
MD5: fb0e357d699819ccb977fe653832472c
SHA1: c3436196eacd2471f907b4604a1eb833f7149416
SHA256: 0537F239350019BEE10B18E463FCFCDBFB0324AABB0491E51CD3172D6F03279D
File Size: 109.06 KB, 109056 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.0.0.38
  • 1.0.0.1
  • 1.0.0.0
Comments XtraTrustDSC
Company Name
  • NCR BRASIL
  • Púlsar Ingenieros Ltda.
  • XtraNet
File Description
  • FieldMapConTecTecnico
  • ProyectoVentasDeSOFT
  • Pulsar.DDJJCertifPDF
  • Sistema.Datos
  • XtraTrustDSC
File Version
  • 2.0.0.38
  • 1.0.0.1
  • 1.0.0.0
Internal Name
  • FieldMapConTec.exe
  • ProyectoVentasDeSOFT.exe
  • Pulsar.DDJJCertifPDF.exe
  • Sistema.Datos.exe
  • XtraTrustDSC.exe
Legal Copyright
  • Copyright © 2018
  • Copyright © 2020
  • Copyright © 2024
  • Copyright © NCR 2015
  • Copyright © Púlsar Ingenieros Ltda. 2010
Legal Trademarks XtraNet
Original Filename
  • FieldMapConTec.exe
  • ProyectoVentasDeSOFT.exe
  • Pulsar.DDJJCertifPDF.exe
  • Sistema.Datos.exe
  • XtraTrustDSC.exe
Product Name
  • FieldMapConTecTecnico
  • ProyectoVentasDeSOFT
  • Pulsar.DDJJCertifPDF
  • Sistema.Datos
  • XtraTrustDSC
Product Version
  • 2.0.0.38
  • 1.0.0.1
  • 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 19
Potentially Malicious Blocks: 1
Whitelisted Blocks: 12
Unknown Blocks: 6

Visual Map

0 ? ? 0 0 ? 0 x 0 0 0 ? 0 ? ? 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱琶峟ʏ耀氅歿畦픋˹耀뫹躧픋˹➇ⵌ㭔隞̃ȁ耀꧌æC RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 820

Related Posts

Trending

Most Viewed

Loading...