Threat Database Trojans Trojan.MSIL.Downloader.CG

Trojan.MSIL.Downloader.CG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,229
Threat Level: 80 % (High)
Infected Computers: 11
First Seen: July 31, 2021
Last Seen: May 16, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.CG on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, potentially leading to unauthorized access, data theft, and other malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.MSIL.Downloader.CG?

Trojan.MSIL.Downloader.CG is a type of Trojan horse malware that can infect your computer through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. The name "Trojan" refers to the malware's ability to disguise itself as a legitimate program or file, allowing it to bypass security defenses and gain unauthorized access to your system. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic intermediate representation of code that can be executed by the .NET Common Language Runtime (CLR).

How Trojan.MSIL.Downloader.CG Operates

Once installed, Trojan.MSIL.Downloader.CG can operate in various ways, depending on its intended purpose. It may attempt to download and install additional malware, such as spyware, adware, or ransomware, onto your system. It can also create backdoors, allowing remote access to your computer, or steal sensitive information, such as login credentials, credit card numbers, or personal data. The malware may also modify system settings, registry entries, or files to maintain its presence and evade detection.

Symptoms of Infection

Infected systems may exhibit various symptoms, including slow performance, frequent crashes, or unexpected behavior. You may notice unusual network activity, such as unfamiliar programs or services running in the background, or suspicious files and folders appearing on your system. Additionally, you may receive alerts from your security software or operating system indicating potential threats or vulnerabilities. However, some malware can operate stealthily, making it difficult to detect without proper scanning and monitoring tools.

How to Remove Trojan.MSIL.Downloader.CG

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files, registry entries, or other components related to Trojan.MSIL.Downloader.CG.
  3. Uninstall any suspicious programs or applications that may be associated with the malware, as they can potentially reinfect your system.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions, plugins, or settings that may have been modified by the malware.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that the malware has been completely removed and that your system is clean.

Conclusion

Removing Trojan.MSIL.Downloader.CG requires a combination of technical expertise and caution. It is essential to follow the steps outlined above and to use reputable security tools to ensure that the malware is completely eliminated from your system. Additionally, it is crucial to maintain good security practices, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or links, to prevent future infections and protect your digital assets.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.CG
Signature status: No Signature

Known Samples

MD5: 20c77aa42f30854e6ba5cca5f7220292
SHA1: 43746d610e0f7cd844f6cb8ab2f2542c4e999aa9
SHA256: A0B9EB4ECEB3118E87FEB57C462AC6C48D9F0E0F53A2475072A5C4494D11C9F4
File Size: 20.48 KB, 20480 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description loader
File Version 1.0.0.0
Internal Name loader.exe
Legal Copyright Copyright © 2017
Original Filename loader.exe
Product Name loader
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 28
Potentially Malicious Blocks: 10
Whitelisted Blocks: 6
Unknown Blocks: 12

Visual Map

0 0 x 0 0 0 ? ? ? x ? x ? ? ? ? x ? ? x x ? x ? x x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m�tX�jg �� �v xy ��T��������%������Bx�<#�#��&� &�-(�(X�(�)�`*J*9*�",��-!R1�1HO1�D5,]9ߔ@V�A��G�IH[uH�pJ��N$N�R20U_*X�.X�_�z`�2b"hc�wc�zh�ri��j�bk`k�ql(�lR  RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data �3�0����4 ��|�>O����Z�� �N��w�Ϛ����Ϛ����Ϛ����Ϛ���r �Ý���ר��m�D�X�e���� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 844

Related Posts

Trending

Most Viewed

Loading...