Threat Database Trojans Trojan.MSIL.Krypt.YDAG

Trojan.MSIL.Krypt.YDAG

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 434
First Seen: June 28, 2021
Last Seen: April 14, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.YDAG on a computer system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the integrity of a system, often leading to unauthorized access, data theft, or other malicious activities. It is essential to understand the nature of this threat and take appropriate measures to remove it and prevent future infections.

What Is Trojan.MSIL.Krypt.YDAG?

Trojan.MSIL.Krypt.YDAG is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name suggests it may be related to MSIL (Microsoft Intermediate Language), which is a part of the .NET Framework, but without more specific information, it's challenging to determine its exact origins or the specific family it belongs to. Trojans are known for their ability to bypass security mechanisms and cause harm to infected systems, making them a significant concern for computer users.

How Trojan.MSIL.Krypt.YDAG Operates

Malware like Trojan.MSIL.Krypt.YDAG typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can perform a variety of malicious actions, including but not limited to, stealing personal data, installing additional malware, or providing unauthorized access to the infected system. The exact operation can vary widely depending on the intentions of the malware creators. Understanding how such malware operates is crucial for developing effective removal and prevention strategies.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Krypt.YDAG infection can be varied and subtle, making it difficult for users to detect the malware without proper scanning tools. Common signs include unexpected changes in system performance, such as slow downs or crashes, appearance of unfamiliar programs or icons, and unexpected network activity. In some cases, the malware may not exhibit noticeable symptoms, emphasizing the importance of regular system scans and updates.

How to Remove Trojan.MSIL.Krypt.YDAG

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download removal tools while minimizing system activity.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only uninstall programs you are certain are not needed by your system.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings that the malware may have altered.
  5. After completing the above steps, reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

The removal of Trojan.MSIL.Krypt.YDAG requires careful and systematic steps to ensure the malware is completely eradicated from the system. It's also crucial to adopt preventive measures, such as keeping software up to date, using strong antivirus programs, and being cautious with email attachments and downloads from the internet. By understanding the nature of this threat and how to remove it, users can protect their systems and data from similar threats in the future. Regular maintenance and vigilance are key to maintaining a secure computing environment.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.YDAG
Signature status: No Signature

Known Samples

MD5: b5bc465434febde0104390f558685bff
SHA1: 76e80c85acc95fdd66fdc5434a86726c3ebf1ec5
SHA256: A6E45522118DEDA688BF11DA7DD6765495960822BE5D433682C86374D1E5F709
File Size: 693.76 KB, 693760 bytes
MD5: e9aed501a999b71ece211131b61e7a6d
SHA1: 62eedb0370c184ea10f12209f4fca4f7783da882
SHA256: 202F9715AD5C4AADE1CFE0ECD7E9396D72381CE5A7F3E4662563F0EBEC745B33
File Size: 2.13 MB, 2131456 bytes
MD5: 8a324e45de05ec09e89e698768898dbe
SHA1: f16105ca0da5f625e1462fa1d1088a42a1eb30fc
SHA256: A6DD268F6E0EFD64D976AA70F4C8E57C38560ED56C99B836CE9224BC15D3A353
File Size: 1.65 MB, 1650176 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 16.0.0.0
  • 1.0.0.0
File Description csrss
File Version
  • 16.10.31418.88
  • 1.0.0.0
Internal Name
  • Steal1.exe
  • VisualStudio.Shell.Framework.dll
Legal Copyright
  • Copyright © 1907
  • © All rights reserved.
Original Filename
  • Steal1.exe
  • VisualStudio.Shell.Framework.dll
Product Name csrss
Product Version 1.0.0.0

File Traits

  • .NET
  • CryptUnprotectData
  • GenKrypt
  • HighEntropy
  • No CryptProtectData
  • ntdll
  • Reactor
  • Reflective
  • RijndaelManaged
  • WriteProcessMemory
Show More
  • x86

Block Information

Total Blocks: 400
Potentially Malicious Blocks: 4
Whitelisted Blocks: 348
Unknown Blocks: 48

Visual Map

0 ? 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? x ? 0 ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.AKM
  • MSIL.AgentTesla.PH
  • MSIL.Mardom.S
  • MSIL.Mardom.SA
  • MSIL.Mardom.SB
Show More
  • MSIL.Mardom.SE
  • MSIL.Stealer.RACC

Registry Modifications

Key::Value Data API Name
HKCU\software\froorbnzjifojri::froorbnzjifojri fRooRBNzjiFOJrI RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
Show More
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange

10 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • CheckRemoteDebuggerPresent
  • IsDebuggerPresent
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams

Related Posts

Trending

Most Viewed

Loading...