Threat Database Trojans Trojan.MSIL.Krypt.MBCA

Trojan.MSIL.Krypt.MBCA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 2,739
Threat Level: 80 % (High)
Infected Computers: 6,463
First Seen: December 31, 2012
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.MBCA on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.MSIL.Krypt.MBCA?

Trojan.MSIL.Krypt.MBCA is a type of malicious software, commonly referred to as a Trojan. The name suggests it is written in MSIL (Microsoft Intermediate Language) and may have encryption capabilities, indicated by "Krypt." Trojans are known for their ability to disguise themselves as legitimate programs, making them difficult to detect. They can allow unauthorized access to a computer, leading to data theft, system compromise, and further malware installation.

How Trojan.MSIL.Krypt.MBCA Operates

Trojan.MSIL.Krypt.MBCA, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means, such as downloading and running infected software, opening malicious email attachments, or clicking on links to compromised websites. Once installed, it can create backdoors for remote access, allowing attackers to control the infected computer, steal sensitive information, or use the computer as a botnet to spread further malware or conduct denial-of-service attacks.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, some common symptoms may indicate the presence of Trojan.MSIL.Krypt.MBCA or similar malware. These include unexpected system crashes, slow computer performance, unfamiliar programs or icons appearing on the desktop, unexpected changes in browser settings, and increased network activity without apparent reason. If you notice any of these symptoms, it is crucial to take immediate action to secure your system.

How to Remove Trojan.MSIL.Krypt.MBCA

  1. Boot into Safe Mode with Networking: This will limit the malware's ability to run and interfere with the removal process. You can do this by restarting your computer and pressing the F8 key repeatedly during boot-up, then selecting Safe Mode with Networking.
  2. Perform a Full Scan with a Reputable Tool: Use an anti-malware tool like SpyHunter to scan your system thoroughly. These tools are designed to detect and remove malware, including Trojans like Trojan.MSIL.Krypt.MBCA.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you do not recognize or that were installed around the time you suspect the infection occurred.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, and Edge to their default settings can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot and Re-scan: After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Krypt.MBCA requires careful and thorough steps to ensure that all components of the malware are eliminated from your system. It's also essential to practice preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, avoiding suspicious downloads, and being cautious with email attachments and links. By taking these steps, you can protect your computer and personal data from the threats posed by Trojan.MSIL.Krypt.MBCA and other malicious software.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MBCA
Signature status: No Signature

Known Samples

MD5: 246c86f3aab94dbc304b2ea39eab7b60
SHA1: 3c1c948ae8d53b431e9d07163dfb7be10f03fa3a
File Size: 579.07 KB, 579072 bytes
MD5: 8c0835b9ccc9d79903a697533f4fcbf4
SHA1: 558bac423f15f4180ff6b6d4f5f5cb191be708f1
File Size: 839.17 KB, 839168 bytes
MD5: 889a8bfcef37dfee1e012db2959b1bcd
SHA1: 594c3fb17d8c8e27caab54ffb1736a1ea50bf4f0
File Size: 2.03 MB, 2025472 bytes
MD5: 3fb224ecfa82ba46117fb65d53b136e5
SHA1: a67a217fb18f89cd2a6e6c00ac8cbb3ef656419b
File Size: 416.26 KB, 416256 bytes
MD5: 32b677c66d4d4b09df9bdc2ba6b2e57b
SHA1: b35f2719f2da4285a9cf4d5db87bcbb2149d3aba
SHA256: E97AF852A9BA045B6937BCF2E549FFC818DEA4A68A986132EC5EDBABAB4690BB
File Size: 407.04 KB, 407040 bytes
Show More
MD5: f78f1aaf924a5c0bcbe320a011c0c187
SHA1: 34e5c68ff5b8824086b0b45c932b42dd770292c7
SHA256: EE2471F1E2A056D159E1ED866B0D15B5B708A5706517E3777B155BAD5884DD8A
File Size: 1.66 MB, 1657344 bytes
MD5: 052d0851bec90a7b6e611d3b0aa79c4d
SHA1: f53cbbe43599a02f6a84afbe3a7b587ec4d8e8a0
SHA256: A249525C0862CC79B729BC6504A3E60ED52260AE67AF6DC7962465A2D10584AA
File Size: 1.65 MB, 1648128 bytes
MD5: bd46344cceef24f0c9be8bf46ef5a7af
SHA1: 46acf782ddcfc498551357de2d6920744eeda1ef
SHA256: 5460BB7902BE8D0A360011CCAE374CC8CCF30E55C37578FFC9455C0A7639B61A
File Size: 720.38 KB, 720384 bytes
MD5: e519504a18b8d62f41f95640286782c8
SHA1: b22431a2d5d9b3ef0250f5abba8928840b683c46
SHA256: D7A5D74DD335C63283721BBC0F1F06CAE3CF50C6D83D13A83B6E42CB9A7AF9BE
File Size: 392.70 KB, 392704 bytes
MD5: b20d080f7470b8c4e04523977fe7cd8f
SHA1: 48bc40247938032460d243168f2acfeb49096b75
SHA256: 92F36F0BB9C84583F6FFBCEF3D244ABFAF5B660754DB2B2B282CA99729D2EAA1
File Size: 1.75 MB, 1745856 bytes
MD5: c1f5a17016a10e51e1878f4d179c58a7
SHA1: 6443eabb1e6460c341a87d123c5577658e418155
SHA256: 2564818C723982F36776E271AE62D29901E061A08E1B1209D377C5802FB8CBE9
File Size: 1.39 MB, 1389568 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 3.1.4.5
  • 3.0.0.0
  • 2.2.500.24
  • 2.0.0.21
  • 2.0.0.0
  • 1.0.11.0
  • 1.0.0.15
  • 1.0.0.1
  • 1.0.0.0
Comments
  • A free, simple, and easy to use text editor like Notepad, but with a dark theme! 😀
  • Control de equipos de refrigeración
  • Desenvolvedor Francis Barra Novais
  • EN Management Program
  • Gestionale per riparazioni Network CAT
  • Programa desenvolvido por Jaime Santos por pura diversão, para ouvir rádios online. Adicione as suas rádios favoritas e divirta-se.
  • Robo Sincronizador do mapdManagement
  • Tired of using a notepad to edit commands? Fill in the inputs on the top of the app, let Lazy Admin do the work for you.
Company Name
  • Guerci AIR
  • JaimeSoft
  • MAPD Informática
  • Millergroup SRL
  • Mills Products
  • Rota Software
  • Run-Insane Innovations
File Description
  • CatAneT
  • DvrCloud 2.0
  • EN
  • Frontier Notepad
  • Internet Prorater
  • ISenseAgent
  • Lazy Admin
  • MAPD Bot Sincronizador WEB - mapdManagement
  • PortugalRadio
  • Wi-Air Control
File Version
  • 3.0.0.0
  • 2.2.500.24
  • 2.0.0.21
  • 1.0.11.0
  • 1.0.0.15
  • 1.0.0.3
  • 1.0.0.1
  • 1.0.0.0
Internal Name
  • CatAneT.exe
  • Control.exe
  • DvrCloud2.0.exe
  • EN.exe
  • Frontier Notepad V2.exe
  • Internet Prorater.exe
  • ISenseAgent.exe
  • Lazy Admin.exe
  • MAPD-BOTSINC.exe
  • PortugalRadio.exe
Legal Copyright
  • Copyright Konnor88© 2014-2019, TMAFE Software 2019
  • Copyright © 2019
  • Copyright © 2020
  • Copyright © 2021
  • Copyright © 2022
  • Copyright © 2022~2023 Ian Cavenaghi
  • Copyright © 2023
  • Copyright © 2025
  • Copyright © Microsoft 2020-2020
  • Copyright © Mills Products 2011
Legal Trademarks
  • Developed by Bill Anderson
  • Mancinelli Martín
  • MAPD Informática
Original Filename
  • CatAneT.exe
  • Control.exe
  • DvrCloud2.0.exe
  • EN.exe
  • Frontier Notepad V2.exe
  • Internet Prorater.exe
  • ISenseAgent.exe
  • Lazy Admin.exe
  • MAPD-BOTSINC.exe
  • PortugalRadio.exe
Product Name
  • CatAneT
  • DvrCloud 2.0
  • EN
  • Frontier Notepad
  • Internet Prorater
  • ISenseAgent
  • Lazy Admin
  • MAPD Bot Sincronizador mapdManagement
  • PortugalRadio
  • Wi-Air Control
Product Version
  • 3.0.0.0
  • 2.2.500.24
  • 2.0.0.21
  • 1.0.11.0
  • 1.0.0.15
  • 1.0.0.3
  • 1.0.0.1
  • 1.0.0.0

Digital Signatures

Signer Root Status
MILLSINC\roberts MILLSINC\roberts Self Signed

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • x64
  • x86

Block Information

Total Blocks: 365
Potentially Malicious Blocks: 5
Whitelisted Blocks: 210
Unknown Blocks: 150

Visual Map

0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? 0 0 ? 0 ? ? 0 0 ? 0 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 0 ? ? ? ? 0 0 ? 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 ? ? ? ? x ? ? 0 ? 0 ? ? ? x 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.GTC
  • MSIL.BadJoke.XE
  • MSIL.Dropper.BGB
  • MSIL.Inject.CCA

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation

3 additional items are not displayed above.

Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • ReadProcessMemory

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 856

Related Posts

Trending

Most Viewed

Loading...