Home Malware Programs Keyloggers Gen.Variant.MSILKrypt

Gen.Variant.MSILKrypt

Posted: March 2, 2011

Gen.Variant.MSILKrypt is verified spyware that records keyboard input for the purpose of stealing passwords and other sensitive information. This infection may also exacerbate damage by other malware, since Gen.Variant.MSILKrypt may be able to drop harmful files on your system in Trojan fashion. Gen.Variant.MSILKrypt is a huge risk to the safety of your machine and a well-defined attack on your privacy, which makes deleting Gen.Variant.MSILKrypt an absolute priority.

Machines Vulnerable to Gen.Variant.MSILKrypt's Stealth Infection

Attacks by Gen.Variant.MSILKrypt may take place on systems running Windows NT, 98, XP, 2000, Server 2008 and various Professional versions of those platforms. Gen.Variant.MSILKrypt can be detected by different names depending on the anti-malware scanner that spots the infection: TR/Crypt.CFI.Gen, Trojan.Win32.Generic.pak!cobra, BackDoor.Cybergate.1, Gen:Trojan.Heur.yq1@rvk7GMp, Generic VB.i and Trojan-Dropper.Win32.VB.arok are all known aliases in popular use.

Your chances of actually seeing Gen.Variant.MSILKrypt before it infects your computer are low; Trojan threats like this one will usually attempt to infect a system in the most deceitful and underhanded way possible. Gen.Variant.MSILKrypt may be bundled with other programs, particularly rogue security products. Gen.Variant.MSILKrypt can also be injected by malicious site code, although your browser and security settings will have to be low for Gen.Variant.MSILKrypt to be allowed entry in most cases.

Gen.Variant.MSILKrypt Ais aDefinitive Spy and Perhaps Worse Yet

Those interested in finding out what the Gen.Variant.MSILKrypt spyware can do to your machine need only look below:

  • Gen.Variant.MSILKrypt is first and foremost a keylogger. Keyloggers record all keyboard-based input and try to snatch up bank account logins, Social Security numbers, passwords and other private information. Keyloggers such as Gen.Variant.MSILKrypt will almost always exhibit very few visual symptoms, since they accomplish their theft best while lying low.
  • Some sources also indicate that Gen.Variant.MSILKrypt is a Trojan. Trojans are able to download and run files without your permission, and usually focus on infesting the system with additional threatening programs like rogue scanners and browser hijackers.
  • Gen.Variant.MSILKrypt may also possess backdoor security-disabling functions. These functions let a remote attacker control your PC; they may choose to attack with a delicate hand or be blunt and damage your computer in obvious ways. The most widely-publicized method of remote attacker exploitation is the use of infected computers for Distributed-Denial-of-Service attacks, which are illegal and highly malicious.

Gen.Variant.MSILKrypt will run without being seen by meddling with your registry. If you suspect this spyware is being anywhere near your hard drive, take immediate action to remove Gen.Variant.MSILKrypt. Even the keylogging threat alone is more than bad enough to make Gen.Variant.MSILKrypt a security risk in the highest degree.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %PROGRAM_FILES%\Gen.Variant.MSILKrypt
    2 %Temp%\lol1.exe
    3 %Temp%\lol2.exe
    4 c:\cleansweep.exe\cleansweep.exe
    5 c:\cleansweep.exe\config.bin
    6 c:\Documents and Settings\All Users\Gen.Variant.MSILKrypt \
    7 c:\Documents and Settings\All Users\Start Menu\Gen.Variant.MSILKrypt \

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Gen.Variant.MSILKrypt[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
Loading...