Threat Database Trojans Trojan.MSIL.Krypt.DSM

Trojan.MSIL.Krypt.DSM

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,700
Threat Level: 80 % (High)
Infected Computers: 49
First Seen: July 8, 2025
Last Seen: July 11, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.DSM on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with comprehensive information about the threat, its operation, symptoms, and most importantly, steps to remove it from your system. Understanding the nature of this threat and taking prompt action is crucial to safeguard your personal data and prevent further system compromise.

What Is Trojan.MSIL.Krypt.DSM?

Trojan.MSIL.Krypt.DSM is identified as a Trojan-type threat. Trojans are malicious programs that disguise themselves as legitimate software but are designed to allow unauthorized access to a computer system. They can be used for a variety of malicious purposes, including data theft, spyware, and ransomware distribution. The name suggests it may involve encryption or cryptographic techniques, but without specific details, it's essential to approach removal with a general understanding of Trojan threats.

How Trojan.MSIL.Krypt.DSM Operates

Trojan.MSIL.Krypt.DSM, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means such as clicking on malicious links, downloading infected software, or opening attachments from unsolicited emails. Once installed, it can create backdoors for remote access, allowing attackers to control the infected system, steal sensitive information, or use the system for malicious activities like spamming or distributing malware.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, some common symptoms include unusual system behavior such as slow performance, frequent crashes, and unexpected pop-ups or ads. You might also notice that your system is connecting to the internet without your input, or you may find programs installed that you did not put there. Sometimes, Trojans can remain dormant, making them harder to detect without proper scanning tools.

How to Remove Trojan.MSIL.Krypt.DSM

  1. Enter Safe Mode with Networking: Restart your computer and enter Safe Mode. This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure your anti-virus software is updated before running the scan to catch the latest threats.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or that were installed around the time you noticed the infection.
  4. Reset Browsers: Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot and Re-scan: After completing the above steps, reboot your system and run another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.MSIL.Krypt.DSM requires careful and systematic steps to ensure your system is thoroughly cleaned. It's also a reminder of the importance of preventive measures such as keeping your operating system and software up-to-date, using strong antivirus software, and being cautious with emails and downloads. By following the removal steps outlined and maintaining good computer hygiene, you can protect your system from similar threats in the future and safeguard your personal data.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.DSM
Signature status: No Signature

Known Samples

MD5: 1edee2235908104682c42dfcc6eb9e1f
SHA1: 5d26bb5df90bc7e6f31b0ad38603db0e8287378a
File Size: 684.54 KB, 684544 bytes
MD5: 654a65df58602224ba1aeb4ae8cda260
SHA1: e6cd1685ecc444fc0b680203af93daf9a1d7c861
File Size: 563.20 KB, 563200 bytes
MD5: c575968b3df5f0a8b2a022d14fab01f6
SHA1: f2c4138136c3bb7227d652ce8a17bd966e5c2477
File Size: 564.74 KB, 564736 bytes
MD5: 1ef3f4623579cefbcc900a2b242da2fb
SHA1: c4a1cd1da3f72ea68738b459a9b4524c7eb1a1fe
File Size: 329.73 KB, 329728 bytes
MD5: 080caf6c300693dbcada721509025289
SHA1: fe2259dc604422da76ab63b9369606b430cb31e5
File Size: 564.74 KB, 564736 bytes
Show More
MD5: b94d3eebff6476dd5ebc101c113d9c33
SHA1: 1a2c1b663abd5e60d1b36cce9f635c3c321fbaa8
SHA256: 41C431DC6129D57E0DF76F13655B4211698A3E1457785E84E85DDD2C1A345E4B
File Size: 570.37 KB, 570368 bytes
MD5: 4d78cb349791b6776d2633922b15a275
SHA1: ea11284df1efb782dd72f4208423392d4626a6ec
SHA256: C074B71C08404244C0C255628BCE4ED016496CFC69C123E8AD5A557325F4EB7A
File Size: 565.25 KB, 565248 bytes
MD5: 599b8b6b1da353611d2cb69f42b6abe8
SHA1: 2ecd2c88a6e520b9fc55560f0bcbb07739896364
SHA256: E18C0DE1C02B441DFD565886636022E976F1B2450E3928C43696B7B1018993AB
File Size: 568.83 KB, 568832 bytes
MD5: 36ac7209abb7af4c36b5884011678f99
SHA1: 94bda496e45763ed3696380a80097a84275eed20
SHA256: C8CF2C9511D58A02D7B261D59F00B190F248533C5BD636C81A98E0B0FB818DAA
File Size: 568.32 KB, 568320 bytes
MD5: 8b996c5d94320785ae80cb190c0ce2f4
SHA1: ba4ab502ad0bf31d1343c805a5276fee3932967f
SHA256: 1DB1CC693410789FA5005D36E3B9345ABE58151F86458A07AFF1D9E605AB6C4E
File Size: 563.20 KB, 563200 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Version 1.0.0.0
Internal Name
  • Bcesuajgcga.exe
  • Dbmppicuecs.exe
  • Gfqclcs.exe
  • Haffginbxji.exe
  • Halvpvx.exe
  • Hlitxmmnmze.exe
  • Iuqsrlzi.exe
  • Lpbas.exe
  • Mcekk.exe
  • Xrcvbunoo.exe
Original Filename
  • Bcesuajgcga.exe
  • Dbmppicuecs.exe
  • Gfqclcs.exe
  • Haffginbxji.exe
  • Halvpvx.exe
  • Hlitxmmnmze.exe
  • Iuqsrlzi.exe
  • Lpbas.exe
  • Mcekk.exe
  • Xrcvbunoo.exe
Product Version 1.0.0.0

File Traits

  • .NET
  • GenKrypt
  • HighEntropy
  • x64
  • x86

Block Information

Total Blocks: 7
Potentially Malicious Blocks: 3
Whitelisted Blocks: 1
Unknown Blocks: 3

Visual Map

x x x ? ? 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.DSM

Files Modified

File Attributes
\device\namedpipe\pshost.133973821311183692.1568.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\__psscriptpolicytest_nbcp3mgt.q23.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_xfww1hg0.0m0.ps1 Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal

21 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
Network Winsock
  • closesocket
  • setsockopt
Process Shell Execute
  • CreateProcess

Shell Command Execution

"powershell.exe" -NoProfile -ExecutionPolicy Bypass -Enc UgBlAGcAaQBzAHQAZQByAC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawAgAC0AVABhAHMAawBOAGEAbQBlACAAJwBEAHIAaQB2AGUAcgBTAHkAcwB0AGUAbQAuAGUAeABlACcAIAAtAEEAYwB0AGkAbwBuACAAKABOAGUAdwAtAFMAYwBoAGUAZAB1AGwAZQBkAFQAYQBzAGsAQQBjAHQAaQBvAG4AIAAtAEUAeABlAGMAdQB0AGUAIAAnAEMAOgBcAFUAcwBlAHIAcwBcAE4AegB5AGQAagBoAHYAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwARAByAGkAdgBlAHIAUwB5AHMAdABlAG0ALgBlAHgAZQAnACkAIAAtAFQAcgBpAGcAZwBlAHIAIAAoAE4AZQB3AC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawBUAHIAaQBnAGcAZQByACAALQBPAG4AYwBlACAALQBBAHQAIAAoAEcAZQB0AC0ARABhAHQAZQApACAALQBSAGUAcABlAHQAaQB0AGkAbwBuAEkAbgB0AGUAcgB2AGEAbAAgACgATgBlAHcALQBUAGkAbQBlAFMAcABhAG4AIAAtAE0AaQBuAHUAdABlAHMAIAA1ACkAKQAgAC0AVQBzAGUAcgAgACQAZQBuAHYAOgBVAHMAZQByAE4AYQBtAGUAIAAtAFIAdQBuAEwAZQB2AGUAbAAgAEgAaQBnAGgAZQBzAHQAIAAtAFMAZQB0AHQAaQBuAGcAcwAgACgATgBlAHcALQBTAGMAaABlAGQAdQBsAGUAZABUAGEAcwBrAFMAZQB0AHQAaQBuAGcAcwBTAGUAdAAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AVABpAG0AZQBMAGkAbQBpAHQAIAAoAE4AZQB3AC0AVABpAG0AZQBTAHAAYQBuACAALQBTAGUAYwBvAG4AZABzACAAMAApACAALQBBAGwAbABvAHcAUwB0AGEAcgB0AEkAZgBPAG4AQgBhAHQAdABlAHIAaQBlAHMAIAAtAEQAbwBuAHQAUwB0AG8AcABJAGYARwBvAGkAbgBnAE8AbgBCAGEAdAB0AGUAcgBpAGUAcwApACAALQBGAG8AcgBjAGUA

Related Posts

Trending

Most Viewed

Loading...