Threat Database Trojans Trojan.MSIL.Krypt.UAB

Trojan.MSIL.Krypt.UAB

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1,740
First Seen: April 22, 2021
Last Seen: October 24, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.UAB on your system indicates a potential security threat that requires immediate attention. This detection name suggests a type of malicious software, but without specific details, it's essential to understand the general characteristics of such threats and how to address them. In this report, we will guide you through the nature of this threat, its operational methods, symptoms of infection, and most importantly, the steps to remove it from your system.

What Is Trojan.MSIL.Krypt.UAB?

Trojan.MSIL.Krypt.UAB is identified as a Trojan-type threat. Trojans are malicious programs that disguise themselves as legitimate software but are designed to allow unauthorized access to a computer system. They can be used to spy on users, steal sensitive information, or disrupt system operation. The name suggests it might be related to MSIL (Microsoft Intermediate Language), which could imply it's designed to operate on Windows systems, but without more specific information, it's crucial to focus on general mitigation strategies.

How Trojan.MSIL.Krypt.UAB Operates

Trojan-type threats like Trojan.MSIL.Krypt.UAB typically operate by deceiving users into installing them. This can happen through various means such as downloading software from untrusted sources, opening malicious email attachments, or visiting compromised websites. Once installed, the Trojan can create backdoors, allowing remote access to the system, steal personal data, or install additional malware. Understanding how Trojans operate is key to preventing future infections and removing current ones.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but may include slow system performance, frequent crashes, unfamiliar programs or icons, unexpected pop-ups, and changes in system settings. Sometimes, infections may not exhibit noticeable symptoms immediately, making regular system checks and updates crucial for early detection. If you suspect your system is infected, it's essential to act quickly to minimize potential damage.

How to Remove Trojan.MSIL.Krypt.UAB

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for internet access to download removal tools. This can usually be done by restarting your computer and pressing the F8 key repeatedly during boot-up, then selecting Safe Mode with Networking.
  2. Download and run a full scan with a reputable anti-malware tool such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the threat.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time you noticed the infection. This can be done through the Control Panel or Settings app, depending on your operating system.
  4. Reset your browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan. This option is usually found in the browser's settings or preferences menu.
  5. Reboot your system and then run another full scan with your anti-malware tool to ensure the threat has been fully removed. Rebooting helps to ensure that any malware that was running in memory is cleared out.

Conclusion

Removing Trojan.MSIL.Krypt.UAB requires a systematic approach to ensure your system is thoroughly cleaned and protected against future threats. By following the steps outlined above and maintaining good cybersecurity practices such as regularly updating your software, using strong, unique passwords, and being cautious with emails and downloads, you can significantly reduce the risk of malware infections. Remember, prevention and vigilance are key components of protecting your digital security.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.UAB
Signature status: No Signature

Known Samples

MD5: 7987c18d52974c6525a620eec6859b7a
SHA1: 2368c00317ab909566de99f9357b5b2f2e94978c
SHA256: 98935779C33329358CAA28C9452C932C58B6F1EE2C1C8EF549B9D08883C537E2
File Size: 296.45 KB, 296448 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 197.98.173.35
Company Name VLC Media Player
File Description Bitdefender Antivirus
File Version 199.299.7.262
Internal Name Microsoft Word Host.exe
Legal Copyright Microsoft Edge Host
Legal Trademarks Adobe Photoshop
Original Filename Microsoft Word Host.exe
Product Name FileZilla Upgrade
Product Version 197.98.173.35

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 1,025
Potentially Malicious Blocks: 914
Whitelisted Blocks: 5
Unknown Blocks: 106

Visual Map

0 0 0 x 0 0 ? ? ? ? x x x x x x x x x x x ? x x x x x x ? ? x x x x x x x x x x x x x x x x x x ? ? x x ? ? ? ? ? x x ? x x x ? x ? x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x ? x x ? x x x x x x x x x x x ? ? ? ? x ? x ? x ? x x x x ? x ? ? ? x x x x x x x x x x x x x x ? x x x x ? x x x ? x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x ? x x x x x x x x x x x x x x x ? x x x x x x ? x x x x x x x x ? x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x x x ? x x x x x ? x x x x ? x x x x x x x x x x x x x x x ? x x x x x x x x ? x x x x x x ? x x x x x x ? x x x x x x ? x x x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x x x ? x x x ? x x x x x x ? x x x x x ? x x x x x ? x x x x x ? x x x x x ? x x x ? x x x x x x x ? x x x x x x ? x x x x x ? x x x x x ? x x x ? x x x x x ? x x x x x x ? x x x x ? x x x x ? x x x x x ? x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x ? x x x x ? x x x x x x ? x x x x x x x x ? x x x x x ? x x x x x x x x ? x x x x ? x x x x ? x x x x x x ? x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x x x x ? x x x x x x ? x x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.YAGC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent

Related Posts

Trending

Most Viewed

Loading...