Threat Database Trojans Trojan.Kreapixel

Trojan.Kreapixel

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,964
Threat Level: 80 % (High)
Infected Computers: 564
First Seen: November 5, 2014
Last Seen: July 11, 2026
OS(es) Affected: Windows

The detection of Trojan.Kreapixel on your system indicates a potential security threat that requires immediate attention. This type of malware can compromise your computer's integrity and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Kreapixel?

Trojan.Kreapixel is a type of malicious software that can infiltrate your computer without your knowledge or consent. The term "Trojan" refers to a broad category of malware that disguises itself as legitimate software, allowing it to evade detection and gain unauthorized access to your system. Trojan.Kreapixel, in particular, may be designed to perform various malicious activities, such as data theft, system compromise, or unauthorized communication with remote servers.

How Trojan.Kreapixel Operates

Once installed, Trojan.Kreapixel can operate in the background, often without visible symptoms. It may exploit vulnerabilities in your operating system or applications to gain elevated privileges, allowing it to modify system settings, install additional malware, or capture sensitive information. The malware may also communicate with its creators or other infected systems to receive updates, transmit stolen data, or participate in malicious activities such as botnet operations.

Symptoms of Infection

While Trojan.Kreapixel may not always exhibit obvious symptoms, you may notice unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also observe unexpected changes to your system settings, suspicious network activity, or unfamiliar pop-ups and advertisements. If you suspect that your system is infected, it is crucial to take immediate action to minimize potential damage.

How to Remove Trojan.Kreapixel

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware components.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or plugins.
  5. Reboot your computer and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Kreapixel from your system requires a combination of technical expertise and caution. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up-to-date, using strong antivirus protection, and being cautious when downloading and installing software, you can reduce the risk of future infections and protect your personal data. Remember to stay vigilant and monitor your system for any signs of suspicious activity, as the threat landscape is constantly evolving, and new malware variants are emerging regularly.

Analysis Report

General information

Family Name: Trojan.Kreapixel
Packers: UPX
Signature status: Root Not Trusted

Known Samples

MD5: acf0309f93e25ff91eb302e3d42c1488
SHA1: e81be89c192d6d94b18687387ed258d9c46b13e2
SHA256: 3102E275A37D7E8D31A9F86F4561B2CBB099EC3473936A33EF1AE928330C3274
File Size: 5.95 MB, 5951568 bytes
MD5: 7d8034b1a8fd44ba3a1cf693776a95b3
SHA1: 9979e61c41ad1a5d30cd60186aabcc4f2f687afe
SHA256: 5DB78F23C149AF3D14685604CF5FB9118381AF3EA19AAAD803CFF9899EC17BC5
File Size: 5.67 MB, 5674568 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name 3 Mo
File Description Webplayer setup Setup
Product Name Webplayer setup
Product Version 1.0

Digital Signatures

Signer Root Status
Kreapixel thawte Primary Root CA Root Not Trusted

Block Information

Total Blocks: 444
Potentially Malicious Blocks: 0
Whitelisted Blocks: 444
Unknown Blocks: 0

Visual Map

0 1 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Crack.K
  • Trojan.Agent.Gen.AAT
  • Trojan.Agent.Gen.DE

Files Modified

File Attributes
c:\users\user\appdata\local\temp\7za.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7za.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\__tmp_rar_sfx_access_check_2926265 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\extract.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\extract.bat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\lanceur.vbs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\lanceur.vbs Synchronize,Write Attributes
c:\users\user\appdata\local\temp\pack.7z Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\pack.7z Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\winrar sfx::c%%users%oebogignc:\users\user\appdata\roaminglocal%temp C:\Users\Oebogign\AppData\Local\Temp RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\applicationassociationtoasts::vbsfile_.vbs RegNtPreCreateKey
HKCU\local settings\software\microsoft\windows\shell\muicache::c:\windows\system32\wscript.exe.friendlyappname Microsoft ® Windows Based Script Host RegNtPreCreateKey
HKCU\local settings\software\microsoft\windows\shell\muicache::c:\windows\system32\wscript.exe.applicationcompany Microsoft Corporation RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 +k�8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee,Vs} kP~ ��1���7 ���ﺃee�� ��1��fe��h�n RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ,k8��8tX��B�8 �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G6�^6�� RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx

Shell Command Execution

(NULL) C:\Users\Oebogign\AppData\Local\Temp\Lanceur.vbs

Trending

Most Viewed

Loading...