Threat Database Trojans Trojan.Micropsia.A

Trojan.Micropsia.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,253
Threat Level: 80 % (High)
Infected Computers: 385
First Seen: May 21, 2021
Last Seen: July 25, 2026
OS(es) Affected: Windows

The detection of Trojan.Micropsia.A on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it is essential to understand its nature and take steps to remove it.

What Is Trojan.Micropsia.A?

Trojan.Micropsia.A is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or harmless. The term "Trojan" refers to the malware's ability to deceive users into installing it, often by bundling it with other software or presenting it as a useful tool. The ".Micropsia.A" part of the name is a specific identifier used by security software to distinguish this particular strain of malware from others.

How Trojan.Micropsia.A Operates

Once installed, Trojan.Micropsia.A can operate in various ways, depending on its intended purpose. It may be designed to steal sensitive information, such as login credentials, credit card numbers, or personal data. It could also be used to install additional malware, hijack system resources, or disrupt normal computer operation. In some cases, Trojans like Trojan.Micropsia.A may be used to create backdoors, allowing unauthorized access to the infected system.

Trojans often exploit vulnerabilities in software or human behavior to gain entry into a system. They may be spread through email attachments, infected downloads, or compromised websites. The malware can also be installed manually by an attacker who has physical access to the computer.

Symptoms of Infection

The symptoms of a Trojan.Micropsia.A infection can vary, but common signs include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups. You may also notice unfamiliar programs or icons on your desktop, or receive alerts from your security software indicating malicious activity. In some cases, the infection may not produce any noticeable symptoms, making it difficult to detect without proper scanning tools.

How to Remove Trojan.Micropsia.A

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. This will help identify and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Micropsia.A requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading and installing new programs, you can help protect your computer from future infections. Remember, prevention is key, but swift action in case of an infection can minimize damage and prevent further compromise of your system and data.

Analysis Report

General information

Family Name: Trojan.Micropsia.A
Signature status: Self Signed

Known Samples

MD5: 1d3660809c4085ce0ebd34160689605a
SHA1: dfc540b6805eec6d3109f619a9ae860f49eef88e
SHA256: 59B04204BE6CAF0E5A0A5F919EFE32197395C5B2A7C3729C720E92D13D01453B
File Size: 9.04 MB, 9036896 bytes
MD5: a39650819c36bbd2e49de87ef108f008
SHA1: 240420621d15b32b026713914644bfc930419b78
SHA256: 922ACEA2654A9A942C9ABE2A662AEC71046283DC9F3895F42A3358CD3664077F
File Size: 6.10 MB, 6103552 bytes
MD5: 5da9d726731771402e6736d65c4059cd
SHA1: 61b2d6d7b978c6591c1bb31edaa14b0477e89e17
SHA256: 38DDC4ACF38EA7C4AE3E878C8F714492654D84EDE255A3E48C2D5E321FD76283
File Size: 9.04 MB, 9037416 bytes
MD5: de97b8e8ff9bfa51182d0483545e1e37
SHA1: d50eb4c74e47325eadac0a895178ea5f2c8fe3ed
SHA256: 717592387114A723B3635D89AE804A6DFA6119046A10EC6F8AF114E815FA1E44
File Size: 9.04 MB, 9036896 bytes
MD5: fa78ca5c272de37328c17d58676191f2
SHA1: b6f907e15a44bbacea127fb41a2f84a47481142f
SHA256: 68D4B65633ADD276DCD21C44606026F304B8D3ABB51B512CCAFCF85AEC44DA4B
File Size: 2.70 MB, 2704896 bytes
Show More
MD5: f18e8d6db49bdbf94283ae0653c537a4
SHA1: 06f91d5b0019cd154bf6910f895f1c5299cd4611
SHA256: 7E7B60FA968D0E17184953357677FA87B9AECF9894C0C69A11DE2EF6FA59A46E
File Size: 9.04 MB, 9036896 bytes
MD5: 511658930500f9a3abd816623cdb610b
SHA1: da022b4a70e6bcdfab6bc13cd23692a8a02b75fd
SHA256: 62025C90FBB314925A93672316880A1BEA98332E24EBA841E1DD0B5B8F9C5E3C
File Size: 6.13 MB, 6134944 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Remote Access Open Source
Company Name
  • AllaKore
  • Microsoft Corporation
File Description
  • AllaKore - Remote
  • Windows Symbolic Debugger Engine
File Version
  • 10.0.16299.309
  • 2.2.0.9
  • 2.0.1.0
  • 1.1.0.8
  • 1.0.1.216
  • 1.0.0.0
Internal Name
  • AllaKore - Remote
  • Microsoft® Windows® Operating System
Legal Copyright
  • AllaKore
  • © Microsoft Corporation. All rights reserved.
Legal Trademarks AllaKore
Original Filename
  • AllaKore - Remote
  • DbgEng.Dll
Product Name
  • AllaKore - Remote
  • Microsoft® Windows® Operating System
Product Version
  • 10.0.16299.309
  • 2.2.0.9
  • 2.0.1.0
  • 1.1.0.8
  • 1.0.0.0
Program I D
  • com.embarcadero.
  • com.embarcadero.Cryptui

Digital Signatures

Signer Root Status
TELESEC AFRICA LIMITED SSL.com EV Root Certification Authority RSA R2 Root Not Trusted
ALLEN RIO SERV. E COM. DE PROD. DE INFORMATICA LTDA thawte SHA256 Code Signing CA - G2 Self Signed

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • packed
  • VirtualQueryEx
  • x86

Block Information

Total Blocks: 12,141
Potentially Malicious Blocks: 214
Whitelisted Blocks: 11,927
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DSS
  • Banker.FD
  • Banload.XH
  • Banload.XJ
  • Casbaneiro.A
Show More
  • Danabot.DI
  • Delf.FC
  • Delf.OD
  • Delf.OF
  • Downloader.TD
  • Gamehack.ODB
  • Gamehack.ODC
  • Grandoreiro.J
  • Injector.JDA
  • InstallMonstr.B
  • Ousaban.VA
  • Stealer.YD
  • Ulise.BE
  • Vadokrist.B

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\dfc540b6805eec6d3109f619a9ae860f49eef88e_0009036896.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\240420621d15b32b026713914644bfc930419b78_0006103552.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\61b2d6d7b978c6591c1bb31edaa14b0477e89e17_0009037416.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d50eb4c74e47325eadac0a895178ea5f2c8fe3ed_0009036896.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\06f91d5b0019cd154bf6910f895f1c5299cd4611_0009036896.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\da022b4a70e6bcdfab6bc13cd23692a8a02b75fd_0006134944.,LiQMAxHB