Threat Database Trojans Trojan.MSIL.Dropper.B

Trojan.MSIL.Dropper.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,206
Threat Level: 80 % (High)
Infected Computers: 11,168
First Seen: January 7, 2013
Last Seen: July 6, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Dropper.B indicates that a potentially malicious program has been identified on your system. This type of threat is categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. Trojans can have various functions, including data theft, remote access, and downloading additional malware. It's essential to address this issue promptly to prevent potential harm to your system and data.

What Is Trojan.MSIL.Dropper.B?

Trojan.MSIL.Dropper.B is a type of malware that may be designed to download and install other malicious programs on your computer. The name suggests that it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the .NET Common Intermediate Language. This allows the malware to potentially run on multiple platforms, making it more versatile and dangerous. Understanding the nature of this threat is crucial for effective removal and prevention of future infections.

How Trojan.MSIL.Dropper.B Operates

Malware like Trojan.MSIL.Dropper.B typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it may connect to command and control servers to receive instructions or download additional malware. This can lead to a range of malicious activities, including but not limited to, stealing personal data, logging keystrokes, or using your computer's resources for cryptocurrency mining. The exact operation can vary widely depending on the specific goals of the malware authors.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Dropper.B infection can be subtle and may not always be immediately apparent. Common signs include unexpected changes to your computer's behavior, such as slow performance, unfamiliar programs or icons, frequent pop-ups, or antivirus warnings. In some cases, you might notice that your browser's homepage has changed, or you're being redirected to unwanted websites. If you suspect that your computer is infected, it's crucial to take action to remove the malware as soon as possible.

How to Remove Trojan.MSIL.Dropper.B

  1. Boot your computer in Safe Mode with Networking. This will help prevent the malware from loading and make it easier to remove.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the malware.
  3. Uninstall any suspicious programs that you don't recognize or that were installed around the time you noticed the infection. Be cautious and only remove programs you're sure are safe to uninstall.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings that the malware may have altered.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that the malware has been fully removed. Repeat this process until no more threats are detected.

Conclusion

Removing Trojan.MSIL.Dropper.B requires careful steps to ensure that all components of the malware are eliminated from your system. It's also important to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading files from the internet. By understanding how Trojans operate and taking proactive steps, you can significantly reduce the risk of malware infections and protect your digital security.

Analysis Report

General information

Family Name: Trojan.MSIL.Dropper.B
Signature status: No Signature

Known Samples

MD5: 27d6ff6740b538e9b8e1c111cfbd0912
SHA1: ee31b25a73403260a2b1de333f87fa3cbca48a83
SHA256: 900F86FB33F1DB088ECC41784EFF1BC5121C0181FE4D319D6FDA2AEB5D8F710D
File Size: 17.76 KB, 17760 bytes
MD5: ac41c4470fec0e475d9ca1617425b1fa
SHA1: 3d6c7c3718bfc84f65dd860297e3762ab105e46a
SHA256: 372974841A82D7E703C8254AA8915CEE1DC57EE1FAE7602B555FD25B9F2C543C
File Size: 9.22 KB, 9216 bytes
MD5: 983e4ad6e5a30d6675ccc5f84d7d8a9c
SHA1: 121e97284efd2f9b9fd25cc1d6aed033371de81c
SHA256: 3D857C91360CF3CD343596B84E9A65AAF509713D8A26CD7F9FC8CEF02232F379
File Size: 22.53 KB, 22528 bytes
MD5: 28e0aa39ae106b9fbdc89366e13f1c62
SHA1: 4c53695548bc8d0e5594c993a874bb1fb076c359
SHA256: C2B80EDCBAC10CF988631FDD2288F41806EF948B9ED224861E9A4AE8C8FE8DF0
File Size: 9.73 KB, 9728 bytes
MD5: 022d7cc3fc7172f61c3c9b21ecfab5c3
SHA1: c0258e77717bb880b38bcc8de78681770cf46240
SHA256: D6DFF42883D1C1B66ACA04FC64A9191620CF73AB949CEFF7692EC38AAE052AE1
File Size: 9.73 KB, 9728 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 7.32.0.0
  • 1.0.0.0
Company Name
  • HP
  • Microsoft
File Description
  • CClnk
  • cddnie-app
  • DockGettingStarted
  • key
  • thesisUI
File Version
  • 7.32.0.0
  • 1.0.0.0
Internal Name
  • CClnk.exe
  • cddnie-app.exe
  • DockGettingStarted.exe
  • key.exe
  • thesisUI.exe
Legal Copyright
  • Copyright © 2022
  • Copyright © 2023
  • Copyright © 2025
  • Copyright © HP 2024
  • Copyright © Microsoft 2018
Original Filename
  • CClnk.exe
  • cddnie-app.exe
  • DockGettingStarted.exe
  • key.exe
  • thesisUI.exe
Product Name
  • CClnk
  • cddnie-app
  • DockGettingStarted
  • key
  • thesisUI
Product Version
  • 7.32.0.0
  • 1.0.0.0

Digital Signatures

Signer Root Status
CLEVO CO. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed

File Traits

  • .NET
  • x64
  • x86

Block Information

Total Blocks: 11
Potentially Malicious Blocks: 0
Whitelisted Blocks: 9
Unknown Blocks: 2

Visual Map

? 0 ? 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Downloader.SRA
  • MSIL.Dropper.BVE
  • MSIL.Gamehack.KPA

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\pshost.134032501483336096.5316.defaultappdomain.ee31b25a73403260a2b1de333f87fa3cbca48a83_0000017760 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\__psscriptpolicytest_5qihnhb5.f1x.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_qf3qv44y.gwa.psm1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\explorer.exe ⺪颾ⷙǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects

26 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • ReadProcessMemory
Keyboard Access
  • GetKeyState

Shell Command Execution

"C:\WINDOWS\explorer.exe" shell:appsFolder\CLEVOCO.FnhotkeysandOSD_6h6z29zh29qx0!App

Related Posts

Trending

Most Viewed

Loading...