Threat Database Trojans Trojan.MSIL.Krypt.YACE

Trojan.MSIL.Krypt.YACE

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: October 28, 2025
Last Seen: November 27, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.YACE indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to infiltrate and damage your computer, often without your knowledge or consent. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further harm.

What Is Trojan.MSIL.Krypt.YACE?

Trojan.MSIL.Krypt.YACE is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan" refers to the fact that this malware often enters a system by masquerading as a harmless or useful application. The ".MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a programming language used by the .NET Framework. The "Krypt" and "YACE" parts of the name may indicate that the malware has encryption or other advanced capabilities.

How Trojan.MSIL.Krypt.YACE Operates

Once installed on a system, Trojan.MSIL.Krypt.YACE can operate in various ways, depending on its intended purpose. Some common behaviors of Trojan horse malware include stealing sensitive information, such as passwords or credit card numbers, installing additional malware, or providing a backdoor for remote access to the infected system. Trojan.MSIL.Krypt.YACE may also attempt to evade detection by anti-virus software or other security measures, making it challenging to remove.

Symptoms of Infection

Systems infected with Trojan.MSIL.Krypt.YACE may exhibit a range of symptoms, including slow performance, frequent crashes, or unusual network activity. You may also notice that your system is behaving erratically or that certain programs are not functioning correctly. In some cases, the malware may not produce any noticeable symptoms, making it difficult to detect without the aid of anti-virus software.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Increased network activity or unusual traffic patterns
  • System crashes or freezes
  • Slow system performance or responsiveness

How to Remove Trojan.MSIL.Krypt.YACE

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Use a reputable anti-virus tool, such as SpyHunter, to perform a full scan of your system and detect any malware or other threats.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Krypt.YACE from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable anti-virus software, you can help to ensure that your system is free from this and other types of malware. Remember to always be cautious when downloading and installing software, and to keep your operating system and security software up to date to prevent future infections.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.YACE
Signature status: No Signature

Known Samples

MD5: fe52552059b8137a41f9435aad7903a7
SHA1: 15ea5e6680d9725efd9eb34440b97e09443ec9a4
SHA256: 5B19FD8FAF5D00D8767F15B918A246D4C0327F277D9606EBAFBC57AA252431A4
File Size: 1.40 MB, 1397248 bytes
MD5: 3499191a58848b734f309164307dead3
SHA1: 207b71030c5d7fdc8974a87b940893fa60ae7bdf
SHA256: 6124803FBB4B0976023C2B5CB867B0443B3DF9FE14F44753B5F8B5093235D243
File Size: 1.63 MB, 1633792 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 1.0.5919.28420
  • 1.0.4986.15296
File Description
  • Aqkjsal
  • Hgfdw
File Version
  • 1.0.7321.10555
  • 1.0.1445.9079
Internal Name
  • Aqkjsal.exe
  • Hgfdw.exe
Legal Copyright
  • Copyright © 2020
  • Copyright © 2024
Original Filename
  • Aqkjsal.exe
  • Hgfdw.exe
Product Name
  • Aqkjsal
  • Hgfdw
Product Version
  • 1.0.7321.10555
  • 1.0.1445.9079

File Traits

  • .NET
  • HighEntropy
  • msil.krypt
  • x64
  • x86

Block Information

Total Blocks: 1,483
Potentially Malicious Blocks: 626
Whitelisted Blocks: 853
Unknown Blocks: 4

Visual Map

0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x x x x x 0 x 0 0 x x x x x 0 0 0 0 0 0 0 0 0 x x x x x x 0 x 0 x 0 x x x x x 0 0 x x 0 x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 0 0 x x 0 x x x x x x x x x x x 0 x 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x x 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 x x 0 0 0 0 x 0 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x 0 x x 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 x 0 x x x x x x x x 0 x 0 x x 0 0 x x x x x 0 0 x x x 0 0 x x x x x x x x 0 0 0 0 x 0 0 x 0 x 0 x 0 0 0 x x 0 0 0 0 x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x 0 0 0 0 0 0 0 0 x x 0 0 x x 0 x 0 0 0 0 x 0 0 x x 0 x 0 x 0 0 x 0 x 0 0 0 0 x 0 x x x x x x 0 0 0 0 x x x x x 0 0 x x x x x 0 0 0 0 0 x x x x x 0 0 0 0 x x x 0 0 0 0 x 0 x 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 x 0 x x x 0 x 0 0 0 x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x 0 x x 0 x 0 0 0 0 0 x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 x 0 0 x x 0 x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 0 x 0 0 x 0 x x x 0 x x 0 x x x 0 x 0 0 x x x x x x x x x 0 x x x 0 0 x 0 x 0 x x x x x x x x x x x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x x 0 0 x 0 x x 0 0 0 0 0 x x x x 0 x 0 x x 0 0 0 x 0 x x x x x x 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 x x x 0 0 x x x x x 0 x x x x x x x x 0 x 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 x x 0 0 0 x 0 x 0 0 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x x x x 0 x 0 x 0 x 0 0 0 0 x 0 0 x 0 x x 0 0 x 0 x x 0 0 0 0 0 x x 0 0 x x x 0 x x x 0 0 x 0 x x x 0 0 0 x 0 x 0 x x 0 x 0 x 0 0 0 0 0 0 0 x x x x x x x 0 x x 0 x x x x 0 0 x x 0 x x x x x x 0 0 0 x 0 x x 0 x 0 x x x 0 x x x x 0 x 0 0 x 0 0 x x x 0 x x x x x x 0 x 0 0 x x x x x x x x x 0 0 x x x 0 0 x x x 0 x 0 0 0 0 x x x x x x x x x x x x x 0 0 x x 0 0 x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 x x 0 0 0 0 x 0 x x x 0 0 x x x x x 0 x 0 x 0 0 x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 x x x x 0 0 0 0 x x 0 x x x 0 x x x x x 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 x x x x 0 x 0 x 0 x 0 0 0 0 0 x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x x 0 0 0 0 x x x 0 0 x 0 x x x x x 0 x x x x x 0 x x x x x x 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 x x 0 0 x 0 x x x 0 x 0 0 x x x x x x x x 0 0 0 x 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.YACE

Files Modified

File Attributes
c:\users\user\appdata\local\temp\adaa4fbc41\lymmqeui.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\tasks\lymmqeui.job Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy�ރ ��^��zeeQVs}kP~��1>��ee�����1��fe��ise��r��se��ue��ve��{e�� RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareObjects
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetContextThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection

Related Posts

Trending

Most Viewed

Loading...