Threat Database Trojans Trojan.MSIL.Krypt.EEEKC

Trojan.MSIL.Krypt.EEEKC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,330
Threat Level: 80 % (High)
Infected Computers: 100
First Seen: September 3, 2025
Last Seen: July 9, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.EEEKC on your system indicates a potentially serious security threat. This type of malware is designed to infiltrate your computer without your knowledge or consent, often through exploited vulnerabilities or social engineering tactics. Understanding the nature of this threat and how it operates is crucial in taking the appropriate steps to remove it and protect your system from future infections.

What Is Trojan.MSIL.Krypt.EEEKC?

Trojan.MSIL.Krypt.EEEKC is identified as a Trojan-type threat, which means it is a malicious program that can cause harm to your computer system. Trojans are known for their ability to disguise themselves as legitimate software, making them difficult to detect. The name suggests it may involve encryption or cryptographic techniques, but without specific details, it's essential to focus on general removal and protection strategies.

How Trojan.MSIL.Krypt.EEEKC Operates

Trojan-type malware, including Trojan.MSIL.Krypt.EEEKC, typically operates by gaining unauthorized access to a computer system. Once inside, it can perform a variety of malicious actions, such as stealing sensitive information, installing additional malware, or providing a backdoor for remote access by attackers. The exact mechanisms can vary widely, but the goal is often to exploit the infected system for financial gain or to expand the attacker's network of compromised machines.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, some common symptoms include unexpected changes to your computer's settings, slow performance, frequent crashes, or the appearance of unwanted programs or toolbars in your web browser. Sometimes, a Trojan might not exhibit any noticeable symptoms at all, making regular system scans crucial for detection.

  • Unexplained changes to system settings or browser configurations
  • Performance issues, such as slower than usual operation
  • Frequent system crashes or freezes
  • Appearance of unwanted software or browser extensions

How to Remove Trojan.MSIL.Krypt.EEEKC

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This can usually be done by restarting your computer and pressing a specific key (such as F8) during boot-up.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the Trojan.
  3. Uninstall any suspicious programs or applications that you do not recognize or no longer need. Be cautious and only remove programs you are certain are safe to uninstall.
  4. Reset your web browsers (e.g., Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full system scan to ensure the malware has been completely removed. Repeat this process if the malware is still detected after the first removal attempt.

Conclusion

Removing Trojan.MSIL.Krypt.EEEKC requires careful and systematic steps to ensure your system is thoroughly cleaned and protected. After removal, it's essential to maintain good security practices, including keeping your operating system and software up to date, using strong, unique passwords, and being cautious with email attachments and links from unknown sources. Regular system scans and backups can also help in early detection and recovery from future threats.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.EEEKC
Signature status: No Signature

Known Samples

MD5: e5fe5767a8e2638b466eeb4e76be1085
SHA1: d5e327b01664de214fb8fda501681b2d20bba9be
SHA256: A334EE89CA8ECF18C0E9458D034B075566E3FF62B1AF431E58F3EABAF1AC53EA
File Size: 9.92 MB, 9923584 bytes
MD5: 1ceda9e93ef9f5b869570460388f3943
SHA1: 2e3df366fbeae9b1742a243baf838b1b56b74e60
SHA256: 2C5A8663BFF6A964370C10C243ED07EB963D538B29BCA00DE3046F69C328A9F7
File Size: 9.90 MB, 9904128 bytes
MD5: a3088679c25ad4801c41f104b757c9fe
SHA1: 04aad2e7dac317ac2d946fef20969de836fb66f2
SHA256: 469FE97495FD1EE1E7F1305D5F9437F69307937AD2C5547BCAA95DC7EA297687
File Size: 9.76 MB, 9761280 bytes
MD5: 4003f542986e03bd137a03ef3afe45b6
SHA1: fd55aa0189b321e485f67e3639703d1f829ed12d
SHA256: F68C7B5DB79FE458E5491040D1074B1121570E5951F22D5C655661941150B983
File Size: 9.76 MB, 9761280 bytes
MD5: 8671b41efdd952112a386fe2d4aee972
SHA1: 7f3d19e3992554fa39082b21eb4b02870758d513
SHA256: 19888DC02C8E96375BBB656477AA19F97BBEB926A0CEA1CC4D582EA9CCD83E1C
File Size: 9.91 MB, 9908736 bytes
Show More
MD5: 6e3a24a6ad18efec6b48ba47a1bea659
SHA1: 03f3da41c13d5e65bffe631ea901ee886fff238d
SHA256: DD86A3E996B53B952E35477B7980929B1C43C42EFEC0EADC618115A22FFB86DC
File Size: 9.68 MB, 9682944 bytes
MD5: 2ece51ad92bc05c4ff5cd87ecfd5b5dd
SHA1: 2cc060736f9e93fe6a9d120643a62d21a28c2cb9
SHA256: FEE1C89111C57655D8A1CEE314B41BF6493E7D410F71932A57C894AD52D4A8CA
File Size: 9.76 MB, 9756672 bytes
MD5: dff16e6eb76f975233537e64647db18b
SHA1: 8689377b0d93b3f6b6aa0163b368a4a472c0803b
SHA256: D4BCE3E48CF3BD52A3910764AC6CA0A724ED6C54830BBF0266632395F997C7D8
File Size: 9.93 MB, 9926656 bytes
MD5: 810eb14cd0761911d7d9ae1969ac2967
SHA1: ddee7cba971364fd7fbfa9357d2f876eff4cc39a
SHA256: E755E343EB24FF4BA7AA775FA7D4A086652923A84AA0717C9705AC05F5AD3140
File Size: 9.76 MB, 9762304 bytes
MD5: a7ebace9f0bd629ffc962b98bff1b508
SHA1: 1f4eacf8f6db45f969f277b750a2594451faa96d
SHA256: 491A2D706255E6F1B65D86B518ADEFF04219491989F45F1F95455E9AD7388FE5
File Size: 9.75 MB, 9751040 bytes
MD5: 2f5efbcf10af106c453d69dcac11fd03
SHA1: 40a0e03a3172ffc2b098e14b15e2934a015f1e88
SHA256: 29F810C464152E0A83893E345E83C1C03B51A58602E689F73B5591AA417F002D
File Size: 9.87 MB, 9870336 bytes
MD5: 85cc45c569da26792fffe452e4e078f1
SHA1: 67e4f342387daeb8d0e66d853a804781e5da55c6
SHA256: 9C305781DCDA410DB3CB0F6E8A51F64A22E8F0A8E51C5BD4FC7D9E9D451D7F69
File Size: 9.93 MB, 9930752 bytes
MD5: d32459b2d551c1749f3dab242e72177f
SHA1: c0c2a815b83b2acf0185476128b54f15b26a671c
SHA256: 11C23AA4C54CA3A005656BB106509643E368198F2E93DD7D1402AFC01CBA1A8C
File Size: 9.47 MB, 9469440 bytes
MD5: 85e55f2b52438527836fea7e5317493d
SHA1: 4ddc7b7969ca4074c76bbfcf9927d0334d154631
SHA256: 48CE35EA766F2547D45039F74EDCAB95BFDEA5F9E1E048DBBF98EBB667D3E87A
File Size: 9.49 MB, 9488896 bytes
MD5: ed91ee57642f44cebaea8d2cfa96627b
SHA1: 36b95414dbdac7bdd476862aa7c367ff073e5eb4
SHA256: A7385766D57FD6A6AAE9FE785DF2E23D250D6E581836C779B01CEB7563DD01F7
File Size: 9.47 MB, 9469440 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • artistique
  • courant
  • evidence
  • Fehler
  • have
  • lugar
  • organisé
  • participants
  • performant
  • project
Show More
  • resolver
  • technical
  • word
File Version 1.0.0.0
Internal Name
  • CrashRpt1403.dll
  • WindowsCodecs.dll
Legal Copyright Copyright © 2023
Original Filename
  • CrashRpt1403.dll
  • WindowsCodecs.dll
Product Name dete
Product Version 1.0.0.0

File Traits

  • .NET
  • dll
  • HighEntropy
  • x64
  • x86

Block Information

Total Blocks: 289
Potentially Malicious Blocks: 140
Whitelisted Blocks: 147
Unknown Blocks: 2

Visual Map

0 x 0 x 0 x 0 x 0 x 0 x 0 ? 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 ? 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x x 0 x 0 x 0 x 0 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Bulz.SH

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2e3df366fbeae9b1742a243baf838b1b56b74e60_0009904128.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\04aad2e7dac317ac2d946fef20969de836fb66f2_0009761280.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\fd55aa0189b321e485f67e3639703d1f829ed12d_0009761280.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7f3d19e3992554fa39082b21eb4b02870758d513_0009908736.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\03f3da41c13d5e65bffe631ea901ee886fff238d_0009682944.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2cc060736f9e93fe6a9d120643a62d21a28c2cb9_0009756672.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8689377b0d93b3f6b6aa0163b368a4a472c0803b_0009926656.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1f4eacf8f6db45f969f277b750a2594451faa96d_0009751040.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\40a0e03a3172ffc2b098e14b15e2934a015f1e88_0009870336.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\67e4f342387daeb8d0e66d853a804781e5da55c6_0009930752.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c0c2a815b83b2acf0185476128b54f15b26a671c_0009469440.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4ddc7b7969ca4074c76bbfcf9927d0334d154631_0009488896.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\36b95414dbdac7bdd476862aa7c367ff073e5eb4_0009469440.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...