Threat Database Trojans Trojan.MSIL.Downloader.CAN

Trojan.MSIL.Downloader.CAN

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,419
Threat Level: 80 % (High)
Infected Computers: 166
First Seen: January 8, 2022
Last Seen: May 12, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.CAN indicates that your system has been compromised by a potentially malicious threat. This type of threat is categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. Trojans can cause significant harm to your system and data, making it essential to understand the nature of this threat and take immediate action to remove it.

What Is Trojan.MSIL.Downloader.CAN?

Trojan.MSIL.Downloader.CAN is a type of malware that has been detected on your system. The name suggests it is a Trojan-type threat, but without more specific information, it's challenging to pinpoint its exact nature or the family it belongs to. Trojans are known for their ability to sneak into systems by masquerading as useful software, and once inside, they can perform a variety of malicious actions, including downloading additional malware, stealing data, or providing unauthorized access to the system.

How Trojan.MSIL.Downloader.CAN Operates

Given its classification as a Trojan, Trojan.MSIL.Downloader.CAN likely operates by exploiting vulnerabilities in the system or by tricking users into installing it. Once installed, it can communicate with its command and control servers to receive instructions, which might include downloading and installing other types of malware. This can lead to a range of malicious activities, from data theft and ransomware attacks to the use of the system for spamming or as part of a botnet for distributed denial-of-service (DDoS) attacks.

Symptoms of Infection

Systems infected with Trojan.MSIL.Downloader.CAN may exhibit a variety of symptoms, although some infections may not display noticeable signs immediately. Common indicators of a Trojan infection include slow system performance, frequent crashes, unexpected pop-ups, and changes to browser settings or the presence of unfamiliar programs. Additionally, if the Trojan is designed to download other malware, the symptoms can vary widely depending on the additional payloads installed.

How to Remove Trojan.MSIL.Downloader.CAN

  1. Boot your system into Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process while still allowing you to download necessary tools.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the Trojan.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the infection was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and run another full scan with your anti-malware tool to ensure that all components of the Trojan have been removed.

Conclusion

The removal of Trojan.MSIL.Downloader.CAN requires careful and immediate action to prevent further damage to your system and data. By following the steps outlined above and maintaining vigilance in your online activities, you can significantly reduce the risk of future infections. Remember, prevention is key, so always be cautious when downloading software, avoid suspicious links and emails, and keep your operating system and security software up to date.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.CAN
Signature status: Self Signed

Known Samples

MD5: cf4584d66c21e4dea9e98b9b929c5a63
SHA1: a74535e5567cc894c8f6b691ecf2e291ebbd618e
SHA256: 65DFCA268A127E8E915D165769850F4E5C410EA0C8088C7E6BD9AC6A775FA0F0
File Size: 33.73 KB, 33728 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description CopiaArquivos
File Version 1.0.0.0
Internal Name AtivaInstancia.exe
Legal Copyright Copyright © 2011
Original Filename AtivaInstancia.exe
Product Name CopiaArquivos
Product Version 1.0.0.0

Digital Signatures

Signer Root Status
DESKTOP-4SRA5JU\IAFBA DESKTOP-4SRA5JU\IAFBA Self Signed

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 38
Potentially Malicious Blocks: 0
Whitelisted Blocks: 35
Unknown Blocks: 3

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Downloader.Tiny.CF
  • MSIL.Injector.XR
  • MSIL.Injector.XS
  • MSIL.Injector.XT
  • MSIL.Krypt.MBWB
Show More
  • MSIL.Krypt.TDL

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • ReadProcessMemory

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 1348

Trending

Most Viewed

Loading...