Threat Database Trojans Trojan.MSIL.Downloader.ACGB

Trojan.MSIL.Downloader.ACGB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,552
Threat Level: 80 % (High)
Infected Computers: 37
First Seen: July 13, 2022
Last Seen: June 1, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.ACGB on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operational characteristics, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.MSIL.Downloader.ACGB?

Trojan.MSIL.Downloader.ACGB is a type of malware that falls under the category of Trojans, which are malicious programs designed to deceive users into installing them on their systems. The name suggests it is a downloader Trojan, implying its primary function is to download additional malicious components from the internet. Understanding the nature of this threat is crucial for effective removal and prevention of future infections.

How Trojan.MSIL.Downloader.ACGB Operates

Trojan.MSIL.Downloader.ACGB, like other Trojans, operates by disguising itself as a legitimate program or file, tricking users into executing it. Once installed, it can perform a variety of malicious actions, including downloading and installing other malware, stealing personal data, or providing unauthorized access to the infected system. The specifics of its operation can vary, but its primary goal is to compromise the security and integrity of the infected computer.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Downloader.ACGB infection can be subtle and may not always be immediately apparent. Common indicators include unusual system behavior, such as slow performance, frequent crashes, or the appearance of unwanted programs or toolbars. Additionally, users may notice changes in their browser settings or unexpected pop-ups and advertisements. Since Trojans can be designed to operate stealthily, some infections may not exhibit noticeable symptoms, making regular system scans crucial for detection.

How to Remove Trojan.MSIL.Downloader.ACGB

  1. Boot your computer in Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process and allow you to download necessary tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the Trojan.
  3. Uninstall any suspicious programs that were installed around the time the Trojan was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure all components of the Trojan have been removed.

Conclusion

Removing Trojan.MSIL.Downloader.ACGB requires a systematic approach to ensure all components of the malware are eliminated from the infected system. By following the steps outlined in this report and maintaining vigilance through regular system scans and safe computing practices, you can protect your computer from this and other malware threats. Remember, prevention is key, so always be cautious when opening email attachments, downloading software, and clicking on links from unknown sources.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.ACGB
Signature status: No Signature

Known Samples

MD5: 711b2158b2f06db07ec68ac9e0afbbea
SHA1: 7aee6249d470b40c9816c7de61d1cb1d6060414a
SHA256: 2B6AF808CA6D134C99E3F8B2B6D100ED2CA1E248D322FA1C28C8D48A8149C894
File Size: 6.77 MB, 6765056 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.1.6
File Version 1.0.1.6
Internal Name updater.exe
Original Filename updater.exe
Product Version 1.0.1.6

File Traits

  • .NET
  • x64

Block Information

Total Blocks: 19,648
Potentially Malicious Blocks: 9,115
Whitelisted Blocks: 10,508
Unknown Blocks: 25

Visual Map

0 x 0 x x x 0 0 0 0 0 0 0 x x x x 0 x x x 0 0 x x 0 0 0 0 0 x x x 0 x x x x x x 0 0 0 x 0 0 x x 0 x x x 0 x x 0 0 x x x x 0 x x x x x x x 0 x 0 x 0 x 0 x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x ? x x 0 x x x x 0 ? 0 x 0 0 0 0 x 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x x 0 x 0 0 0 x 0 0 0 0 0 0 x x 0 0 x x x 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 x x x x x x x x x x x 0 x 0 x 0 x x 0 x 0 0 0 x 0 0 x 0 x x 0 x 0 x x 0 0 x x x x x x 0 x x 0 0 x 0 x x x x 0 x x x x x x x 0 x x 0 x x 0 x 0 x x 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 x x x x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x x 0 x x 0 x x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x x 0 0 x 0 x x 0 0 x x 0 0 0 x x x 0 0 x x 0 0 0 0 x x x 0 x x x x x x x x x x x x x x 0 0 x x 0 x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x 0 x 0 x x x x x x x x x x x x x x x x 0 x x x 0 x x x 0 x 0 x 0 x x x x x x x x x x 0 x 0 x 0 x x x x x x x x 0 x x x x x x x x 0 x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x x 0 0 x x x x x 0 x x x x x x 0 x x x x 0 x x 0 x x x x x 0 0 x x x x x x 0 0 0 0 0 0 x x 0 x 0 x x x x x 0 x 0 x x x x x 0 x x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x x x x x x 0 0 x x x 0 x x x 0 0 0 0 0 x x x 0 0 x 0 x x x 0 0 x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x x x x x 0 x 0 x x x 0 x x x x x x 0 x x 0 0 0 x x x x x x x x 0 0 x x 0 x 0 x x x x 0 x x 0 x x x x x x x x x x x 0 x 0 0 0 x x 0 x 0 x 0 x x x x x x 0 x x x x x x x 0 0 0 0 x x x x x x x x 0 x x x 0 x x x x x x x 0 x 0 0 x 0 x x x x 0 0 0 x 0 0 0 x 0 0 x x x x x x 0 0 0 0 0 0 x x x x x x x x x 0 x x x x 0 0 0 x 0 0 0 0 x x x 0 x x 0 0 0 x 0 0 x x x x 0 0 0 0 x x x x x 0 x 0 0 x x x x x 0 x x x 0 0 0 x x x 0 x x x x x x x x x x x x x x x x 0 x 0 x x 0 0 x x x x 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x x 0 x x 0 0 0 0 0 0 x x 0 0 0 x x x x 0 x x 0 x x x x 0 x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x 0 0 x x x x 0 0 0 0 0 0 0 0 x x x 0 x x x x 0 0 x 0 x x x x 0 0 x 0 0 x x x x 0 x 0 0 0 x x x x x x x 0 x x x x 0 0 0 0 0 0 x x x x x x x 0 x x x x x 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 x x 0 x 0 0 x 0 0 0 x 0 x 0 x x x x 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x x x x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x x 0 x 0 0 x 0 0 x 0 0 x 0 0 0 x 0 0 x 0 0 x 0 0 0 x x x 0 x 0 0 x x x x 0 x x 0 x 0 x 0 x 0 x x 0 x 0 x 0 x x x 0 0 0 x x x x 0 x x x 0 0 0 x x x x x x x x x x x x 0 0 x 0 0 0 0 x 0 x x x x x x x x 0 0 0 x x x x x x 0 0 x x x x x x x x 0 x x x x 0 x x x 0 x 0 0 0 0 0 0 x 0 x 0 x x 0 x 0 x x x x x 0 0 x 0 0 x x x x 0 x x x x 0 x 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x x x x x x x 0 0 x 0 x x x 0 x x x x x x x x x x x 0 x 0 x 0 x x x 0 0 x x x x x x x x 0 0 0 0 x 0 x x x x x 0 x 0 0 x 0 x x x 0 x 0 0 x x x x x x x 0 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x 0 x x 0 x x 0 x 0 x x 0 0 x x x x 0 x 0 0 x 0 x x x x x x x x x x x 0 0 0 x x x x x x 0 0 0 x x x x x 0 x x 0 x x 0 0 0 x x 0 0 x 0 x 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Downloader.ACGB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent

Trending

Most Viewed

Loading...