Threat Database Trojans Trojan.MSIL.Downloader.CAACA

Trojan.MSIL.Downloader.CAACA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 25
First Seen: June 18, 2022
Last Seen: November 26, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.CAACA on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system.

What Is Trojan.MSIL.Downloader.CAACA?

Trojan.MSIL.Downloader.CAACA is identified as a Trojan-type threat, which typically means it is a type of malware that disguises itself as legitimate software but actually allows unauthorized access to the victim's system. The name suggests it may be involved in downloading additional malicious components, but without specific details, it's crucial to approach this with a general understanding of Trojan horse malware. These threats are known for their ability to evade detection by traditional antivirus software, making them particularly dangerous.

How Trojan.MSIL.Downloader.CAACA Operates

While the exact operational details of Trojan.MSIL.Downloader.CAACA are not provided, Trojans generally operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can perform a variety of malicious activities, including data theft, installation of additional malware, and providing backdoor access to attackers. The "Downloader" part of the name implies it may be designed to download and install other malicious programs, further compromising the security of the infected system.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but may include unusual system behavior, such as slow performance, frequent crashes, or the appearance of unwanted programs or toolbars. You might also notice changes in your browser settings or the presence of pop-ups and unwanted advertisements. In some cases, the infection may not display obvious symptoms, making regular system scans crucial for detection.

How to Remove Trojan.MSIL.Downloader.CAACA

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Conduct a Full Scan: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any associated malware.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall anything that looks suspicious or that you do not recognize.
  4. Reset Your Browser: If your browser has been affected, reset it to its default settings. This applies to browsers like Chrome, Firefox, and Edge. Be aware that this will remove all extensions, so you will need to reinstall any legitimate ones afterward.
  5. Reboot and Re-scan: After taking the above steps, reboot your system and perform another scan to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.MSIL.Downloader.CAACA requires careful and methodical steps to ensure your system is thoroughly cleaned and protected. It's also important to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening emails or downloading files from the internet. By following the removal steps outlined and maintaining good cybersecurity practices, you can protect your system from this and other potential threats.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.CAACA
Signature status: No Signature

Known Samples

MD5: e9b3efa1751d49f2afe5f8699c9343fa
SHA1: 1cd7e697c8a87ae95070c584dc0a1cfdcbd6dac1
SHA256: A51E301F6D7463B81A460174B90ABF9B26B1893F64DE09C8AA175C21DDE62D2B
File Size: 45.06 KB, 45056 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Version 1.0.0.0
Internal Name CPLApplet.dll
Original Filename CPLApplet.dll
Product Version 1.0.0.0

File Traits

  • .NET
  • dll
  • HighEntropy
  • NewLateBinding
  • x64

Block Information

Total Blocks: 28
Potentially Malicious Blocks: 9
Whitelisted Blocks: 19
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSILZilla.FK

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 㵖ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 沈 䠱O噀ñ᝹ʁ傄ëķ駃ó䧌VߙĤ⣳ġj鈄ĞꩠŖ RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 沉 䠱O噀ñ᝹ʁ傄ëķ駃ó䧌VߙĤ⣳ġj鈄ĞꩠŖÉ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 沊 䠱O噀ñ᝹ʁ傄ëķ鶝’駃ó䧌VߙĤ⣳ġj鈄ĞꩠŖÉ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 沋 䠱O噀ñ᝹ʁ傄ëķ鶝’淃駃ó䧌VߙĤ⣳ġj鈄ĞꩠŖÉ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreatePortSection
Show More
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelIoFileEx
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory

22 additional items are not displayed above.

Trending

Most Viewed

Loading...