Threat Database Trojans Trojan.MSIL.Krypt.ZADDB

Trojan.MSIL.Krypt.ZADDB

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: June 23, 2025
Last Seen: November 27, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.ZADDB on your system indicates a potential security threat. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to take immediate action to remove it. In this report, we will provide you with general guidance on how to deal with this threat and prevent future infections.

What Is Trojan.MSIL.Krypt.ZADDB?

Trojan.MSIL.Krypt.ZADDB is a type of Trojan horse malware that can infect your system through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. Once installed, it can perform a range of malicious activities, including data theft, system compromise, and disruption of normal computer functions. The name itself does not necessarily indicate a specific malware family, but rather a generic classification of the threat.

How Trojan.MSIL.Krypt.ZADDB Operates

Trojan.MSIL.Krypt.ZADDB, like other Trojans, operates by disguising itself as a legitimate program or file, allowing it to evade detection and gain access to your system. Once inside, it can create backdoors, allowing remote access to your computer, and can also spread to other systems through network connections. The malware can also modify system settings, disable security software, and install additional malicious programs.

Symptoms of Infection

Identifying the symptoms of a Trojan.MSIL.Krypt.ZADDB infection can be challenging, as the malware is designed to remain stealthy. However, some common signs of infection include slow system performance, frequent crashes, and unusual network activity. You may also notice that your system is behaving erratically, with unexpected pop-ups, redirects, or changes to your browser settings. If you suspect that your system is infected, it's crucial to take immediate action to prevent further damage.

How to Remove Trojan.MSIL.Krypt.ZADDB

To remove Trojan.MSIL.Krypt.ZADDB from your system, follow these steps:

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a clean removal process.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another scan to ensure that the malware has been completely removed.

By following these steps, you can effectively remove Trojan.MSIL.Krypt.ZADDB from your system and prevent future infections.

Conclusion

Removing Trojan.MSIL.Krypt.ZADDB from your system requires a combination of technical expertise and caution. By following the steps outlined in this report, you can effectively eliminate the threat and prevent future infections. It's essential to remain vigilant and take proactive measures to protect your system, including keeping your operating system and software up-to-date, using strong antivirus software, and avoiding suspicious downloads and email attachments. By taking these precautions, you can ensure the security and integrity of your computer and protect your personal data from malicious threats.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.ZADDB
Signature status: Self Signed

Known Samples

MD5: 89fe0f4f50ef5f9c8515d0c5eb8da650
SHA1: 729a7910e87741794fcec8c9b3142690c36e7df8
SHA256: CF8999D737E65549F5AF5DA3723E72D954190699F3D72CC0FF80DAAEA6B3B3D8
File Size: 1.56 MB, 1562792 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 2.0.0.3
Comments A Guna Framework Custom Guna .NET controls
Company Name Sobatdata Software
File Description Guna UI2 WinForms
File Version 2.0.0.3
Internal Name Guna.UI2.dll
Legal Copyright Copyright © 2020
Legal Trademarks Sobatdata Software
Original Filename Guna.UI2.dll
Product Name Guna UI2 WinForms
Product Version 2.0.0.3

Digital Signatures

Signer Root Status
Sobatdata Software Sobatdata Software Self Signed

File Traits

  • .NET
  • dll
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 6,483
Potentially Malicious Blocks: 1,892
Whitelisted Blocks: 4,591
Unknown Blocks: 0

Visual Map

x x x x 0 0 0 0 0 0 0 0 x 0 x x x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x x x x 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 x x x x x x x x x x x 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x x x x 0 0 0 0 0 x x x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 x x x x x x x x 0 x x x x x x 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x x x x x x x 0 x x x x x 0 0 0 0 0 x x x 0 0 0 0 x x x x 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x x x x 0 x x 0 0 x 0 0 x x 0 0 0 0 0 x 0 x 0 x x x 0 x 0 x 0 x x x 0 0 x x 0 x x 0 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x x x x x x x x x x x 0 0 0 0 0 0 x 0 x x x 0 x x x x 0 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 x 0 x x 0 x 0 0 x 0 x 0 x x 0 x 0 x 0 x x 0 x 0 x 0 0 0 x 0 x x 0 0 x x x x x x x 0 0 0 0 x x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 x x x x x x x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x 0 x x x 0 x 0 0 0 0 0 x 0 0 0 x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x 0 0 x 0 x x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 x 0 x x x 0 0 0 x 0 0 x 0 0 0 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x x 0 0 0 0 x x x x x x x x x x x x x x 0 0 0 x x x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 x x x x x x x x x x x x x 0 0 0 0 x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 x x x x x x 0 0 x x 0 x 0 0 0 x x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x x x x x 0 x 0 0 0 0 0 0 0 x x x x x x 0 0 x 0 x x 0 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 x x x x 0 0 0 0 0 x x x x x x 0 0 x 0 0 0 x 0 x x x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x x 0 0 x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 x x x 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 0 0 x x x 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x 0 0 x x x x 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 x 0 0 0 x 0 0 0 0 x 0 x x x x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 0 0 x 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.ZADDB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...