Threat Database Trojans Trojan.MSIL.Krypt.ABT

Trojan.MSIL.Krypt.ABT

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,993
Threat Level: 80 % (High)
Infected Computers: 554
First Seen: August 11, 2021
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.ABT indicates that a potentially malicious program has been identified on your system. This name suggests that the threat is a type of Trojan, which is a broad category of malware that can perform a variety of malicious actions. It's essential to understand the nature of this threat and take appropriate steps to remove it and protect your system.

What Is Trojan.MSIL.Krypt.ABT?

Trojan.MSIL.Krypt.ABT is a type of malware that can compromise the security and integrity of your system. The specifics of its operation and the exact nature of its malicious activities can vary, but it is generally designed to evade detection and persist on the system. Malware like this can be used for a range of nefarious purposes, including data theft, unauthorized access, and disruption of system operation.

How Trojan.MSIL.Krypt.ABT Operates

Malware operates by exploiting vulnerabilities in software or manipulating users into installing it. Once installed, it can communicate with its command and control servers to receive instructions, which might include stealing sensitive information, installing additional malware, or using the infected system for malicious activities like spamming or participating in distributed denial-of-service (DDoS) attacks. The exact mechanisms and goals can vary widely among different types of malware.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and might not always be immediately apparent. Common signs include unexpected changes to your system, such as new icons on your desktop, unfamiliar programs, or changes to your browser's homepage. You might also notice that your system is running more slowly than usual, or that certain programs are not functioning correctly. In some cases, you might receive alerts from your security software indicating that it has blocked a suspicious activity.

  • Unexplained system crashes or freezes
  • New, unfamiliar programs or icons
  • Changes to your browser settings or homepage
  • Pop-ups or unexpected advertisements
  • Slow system performance

How to Remove Trojan.MSIL.Krypt.ABT

  1. Boot your system into Safe Mode with Networking. This will help prevent the malware from loading and make it easier to remove.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time you noticed the infection. Be cautious and only uninstall programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Krypt.ABT requires careful and methodical steps to ensure that all components of the malware are eliminated from your system. It's crucial to use reputable security software and follow best practices for system security to prevent future infections. Keeping your operating system, software, and security tools up to date can significantly reduce the risk of malware infections. Always be cautious when clicking on links, opening email attachments, or installing new software, as these are common vectors for malware distribution.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.ABT
Signature status: No Signature

Known Samples

MD5: 49f518369ebfe7e7738636a804bbd091
SHA1: a51780419dbb627b74d44c7f1f8424e5b01524bf
SHA256: B8CBFE0971076047892B62582910F4EC8CA03BBB3E4B4BC46DBB900217AAE199
File Size: 690.18 KB, 690176 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Version 1.0.0.0
Internal Name Oqijq.exe
Original Filename Oqijq.exe
Product Version 1.0.0.0

File Traits

  • .NET
  • GenKrypt
  • HighEntropy
  • x64

Block Information

Total Blocks: 7
Potentially Malicious Blocks: 2
Whitelisted Blocks: 2
Unknown Blocks: 3

Visual Map

x ? ? x 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
Other Suspicious
  • AdjustTokenPrivileges

Related Posts

Trending

Most Viewed

Loading...