Threat Database Trojans Trojan.MSIL.Small.AL

Trojan.MSIL.Small.AL

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,453
Threat Level: 80 % (High)
Infected Computers: 9
First Seen: March 19, 2022
Last Seen: July 5, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Small.AL on your system indicates a potential security threat that requires immediate attention. This detection name suggests a type of malicious software, but without more specific information, it's essential to understand the general characteristics of such threats and how to address them.

What Is Trojan.MSIL.Small.AL?

Trojan.MSIL.Small.AL is identified as a Trojan-type threat, which means it is designed to allow unauthorized access to a computer system. Trojans can be used to steal sensitive information, install additional malware, or provide a backdoor for remote access by an attacker. The name itself does not specify a known malware family but indicates it is written in MSIL (Microsoft Intermediate Language), suggesting it is designed to run on Windows platforms.

How Trojan.MSIL.Small.AL Operates

Trojan horses like Trojan.MSIL.Small.AL typically operate by disguising themselves as legitimate programs or files. Once executed, they can perform a variety of malicious actions, including data theft, keystroke logging, and the installation of additional malware. They may also attempt to connect to command and control servers to receive further instructions or transmit stolen data. Understanding how these threats operate is crucial for taking appropriate measures to protect your system and data.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but may include unusual system behavior, such as unexpected pop-ups, slow performance, or frequent crashes. You might also notice unfamiliar programs or toolbars in your browser, or find that your browser's homepage has been changed without your consent. In some cases, the presence of a Trojan may not be immediately apparent, making regular system scans with anti-virus software an essential part of computer maintenance.

How to Remove Trojan.MSIL.Small.AL

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to gain better control over your system.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the Trojan.
  3. Uninstall any recently installed programs that you do not recognize or that were installed around the time the Trojan was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full system scan to ensure that all malware has been removed.

Conclusion

Removing Trojan.MSIL.Small.AL and preventing future infections require a combination of effective anti-virus tools, safe computing practices, and vigilance. Keeping your operating system, browsers, and other software up to date can help protect against known vulnerabilities that Trojans and other malware often exploit. Regularly backing up important data and being cautious when opening email attachments or downloading software from the internet are also crucial steps in safeguarding your digital security.

Analysis Report

General information

Family Name: Trojan.MSIL.Small.AL
Signature status: No Signature

Known Samples

MD5: 02530808e3db8c91b50bf56d05ad80c3
SHA1: 0d1b22f7354c3aba1a4aca06071f1bd8d9727437
SHA256: 9AE8AE96AC4BAB7F3F006FD38F681EF022849EBA9035752D12DC5D4F94A14B95
File Size: 266.24 KB, 266240 bytes
MD5: 7bf1729e4693be82991e81a43e04511d
SHA1: 68d597b2f4e3af267829092092a282de1ba5afa7
SHA256: 017C99F1C1A8FA88B36C0090240DB41AF3360B62644A1378520D3EDED62D262E
File Size: 1.09 MB, 1086228 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 3.1.0.4
Comments This installation was built with Inno Setup.
Company Name
  • code.bjorninge.no
  • MEDWARE Sistemas Médicos Ltda
File Description
  • FloatingGlucose Setup
  • WebCam - Medware Clínicas
File Version 3.1.0.4
Internal Name WebCam.exe
Legal Copyright Copyright © 2015
Original Filename WebCam.exe
Product Name
  • FloatingGlucose
  • Medware Clínicas WebCam
Product Version
  • v.1.5.1
  • 3.1.0.4

File Traits

  • .NET
  • HighEntropy
  • x86

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 736

Related Posts

Trending

Most Viewed

Loading...