Threat Database Trojans Trojan.MSIL.Downloader.IJCJ

Trojan.MSIL.Downloader.IJCJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,816
Threat Level: 80 % (High)
Infected Computers: 355
First Seen: August 16, 2022
Last Seen: May 29, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.IJCJ on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operation, symptoms, and most importantly, steps to remove it from your computer. It's crucial to address this issue promptly to prevent any further damage or data compromise.

What Is Trojan.MSIL.Downloader.IJCJ?

Trojan.MSIL.Downloader.IJCJ is identified as a Trojan-type threat. Trojans are malicious programs that can allow unauthorized access to a user's system, often disguising themselves as legitimate software. The name suggests it may be involved in downloading additional malicious components, potentially leading to more severe infections. Understanding the nature of this threat is key to taking the right steps in removing it and securing your system.

How Trojan.MSIL.Downloader.IJCJ Operates

Trojan.MSIL.Downloader.IJCJ, like other Trojans, may operate by exploiting vulnerabilities in software or by deceiving users into installing it, often bundled with other programs. Once installed, it can download and install additional malware, steal sensitive information, or provide backdoor access to hackers. The specifics of its operation can vary, but the end goal is typically to compromise the security and integrity of the infected system for malicious purposes.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow performance, or programs starting automatically. Additionally, you might notice changes in your browser settings or the presence of unfamiliar programs. Since Trojans can act as backdoors for other malware, any suspicious activity should be investigated promptly.

How to Remove Trojan.MSIL.Downloader.IJCJ

  1. Enter Safe Mode with Networking: Restart your computer and enter Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process while still allowing you to download necessary tools.
  2. Perform a Full Scan: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure your antivirus software is updated before scanning to detect the latest threats.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you don't recognize or that were installed around the time the malware was detected.
  4. Reset Your Browser: If your browser has been affected, reset it to its default settings. This can be done in the settings menu of Chrome, Firefox, Edge, or any other browser you use.
  5. Reboot and Re-scan: After completing the above steps, reboot your computer and perform another scan with your anti-malware tool to ensure all components of the Trojan have been removed.

Conclusion

Removing Trojan.MSIL.Downloader.IJCJ requires careful and methodical steps to ensure all components are eliminated from your system. By following the guidance provided, you should be able to remove the threat and secure your computer. Remember, prevention is key; keeping your software up to date, using strong antivirus protection, and being cautious with emails and downloads can significantly reduce the risk of future infections. If you're unsure about any part of the removal process, consider consulting with a professional to ensure your system is thoroughly cleaned and protected.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.IJCJ
Signature status: No Signature

Known Samples

MD5: e89f9fb82416c2fdf47115f28e6c7f75
SHA1: d3c089cda860ddd25c617b8b58d1d1b3c6d8f55a
SHA256: 887C7E4CFC042677D081095642C35B28E961C3A2B79E06C2E84199618720E0E3
File Size: 530.94 KB, 530944 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Win32 Cabinet Self-Extractor
File Version 11.00.17763.1 (WinBuild.160101.0800)
Internal Name Wextract
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename WEXTRACT.EXE .MUI
Product Name Internet Explorer
Product Version 11.00.17763.1

File Traits

  • .NET
  • big overlay
  • x86

Block Information

Total Blocks: 93
Potentially Malicious Blocks: 33
Whitelisted Blocks: 60
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 x 0 x x 0 x 0 0 x 0 x 0 0 x x 0 0 x 0 x 0 x 0 x 0 0 0 x 0 x x x x x x 0 x 0 x x 0 x 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 x 0 x 0 0 1 x 0 2 0 0 0 0 0 0 0 0 1 1 0 0 2 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Coinminer.QGA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\setup_~1.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\setup_~1.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Eehldwgf\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenSection
Show More
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Shell Execute
  • CreateProcess
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams

Shell Command Execution

C:\Users\Eehldwgf\AppData\Local\Temp\IXP000.TMP\SETUP_~1.EXE

Trending

Most Viewed

Loading...