Threat Database Trojans Trojan.MSIL.Krypt.YBCH

Trojan.MSIL.Krypt.YBCH

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: April 24, 2023
Last Seen: November 26, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.YBCH on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its characteristics, and steps to remove it from your computer. It is essential to understand that Trojans are malicious programs designed to compromise the security of a system, often by disguising themselves as legitimate software.

What Is Trojan.MSIL.Krypt.YBCH?

Trojan.MSIL.Krypt.YBCH is identified as a Trojan-type threat, which typically means it is designed to allow unauthorized access to a computer system or to disrupt its operation. The name suggests it may be related to or masquerade as a component of a larger malicious framework, but without specific details, it's crucial to approach removal with a broad strategy that addresses potential vulnerabilities and malicious behaviors.

How Trojan.MSIL.Krypt.YBCH Operates

Trojans like Trojan.MSIL.Krypt.YBCH can operate in various ways, often depending on their intended purpose. They may be designed to steal sensitive information, install additional malware, provide backdoor access to hackers, or disrupt system operation. These threats can be particularly dangerous because they can be tailored to evade detection by traditional security software, making them challenging to identify and remove without proper tools and techniques.

Understanding the exact operation of Trojan.MSIL.Krypt.YBCH without specific telemetry data is difficult, but it's clear that its presence poses a significant risk to system security and integrity. Therefore, taking comprehensive steps to remove it and prevent future infections is vital.

Symptoms of Infection

Systems infected with Trojan.MSIL.Krypt.YBCH may exhibit a range of symptoms, including but not limited to, unusual system behavior, unexpected changes in settings, appearance of unwanted programs or files, and significant slowdowns in system performance. However, some Trojans are designed to operate silently, making them difficult to detect without the aid of security software.

  • Unexplained changes in system settings or files
  • Appearance of suspicious programs or applications
  • System crashes or instability
  • Unusual network activity

How to Remove Trojan.MSIL.Krypt.YBCH

  1. Boot your computer into Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the Trojan.
  3. Uninstall any recently installed or suspicious programs that could be related to the Trojan.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full scan to ensure that all remnants of the Trojan have been removed.

Conclusion

Removing Trojan.MSIL.Krypt.YBCH from your system requires careful and thorough action to ensure all components of the malware are eliminated. By following the steps outlined above and maintaining vigilant system monitoring, you can help protect your computer from future threats. Remember, prevention is key, so keeping your operating system, software, and security tools up to date, along with practicing safe computing habits, is crucial in avoiding malware infections.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.YBCH
Signature status: No Signature

Known Samples

MD5: 0d041ee778f9abed18c706a66af3bd80
SHA1: eb4c86f76e5130bcd6e88b2c6765470f06e122fb
SHA256: 496C28C72156FB1F5213E21719737FEFC12B9A3D31145A4ECD3B77492136B467
File Size: 141.82 KB, 141824 bytes
MD5: bc5d8b9b145cc944afacb4304ca6819a
SHA1: d5883a67163b46677aed02576679fa8d74dc5f77
SHA256: 06EAF2A32E8B97DB465B268E32E100224C292359D8FF623273A3F188DDDA674B
File Size: 162.30 KB, 162304 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 3.6.0.0
  • 1.0.0.0
File Version
  • 3.6
  • 1.0.0.0
Internal Name Stub.exe
Legal Copyright Copyright © 2021
Original Filename Stub.exe
Product Version
  • 3.6
  • 1.0.0.0

File Traits

  • .NET
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 34
Potentially Malicious Blocks: 10
Whitelisted Blocks: 11
Unknown Blocks: 13

Visual Map

0 0 0 0 0 0 0 ? ? ? ? x x x x x 0 ? x x ? ? ? ? x ? x x 0 ? ? ? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\tivumueds Synchronize,Write Attributes
c:\users\user\appdata\local\temp\tivumueds\client Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\explorer.exe 隯䔨彘ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe, C:\Users\Wykoavmh\AppData\Local\Temp\tiVUMUeds\Client RegNtPreCreateKey
HKCU\ms-settings\shell\open\command:: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -Command Add-MpPreference -ExclusionPath 'C:\Users\Wykoavm RegNtPreCreateKey
HKCU\ms-settings\shell\open\command::delegateexecute RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent

Shell Command Execution

C:\Windows\explorer.exe (NULL)
C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe" Client part-pcs.at.ply.gg 61489 ihzhyCegq

Related Posts

Trending

Most Viewed

Loading...