Threat Database Trojans Trojan.MSIL.Dropper.JB

Trojan.MSIL.Dropper.JB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,083
Threat Level: 80 % (High)
Infected Computers: 75
First Seen: January 26, 2022
Last Seen: June 4, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Dropper.JB on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to infiltrate your computer and cause harm, making it essential to understand its nature and take steps to remove it. In this report, we will provide an overview of Trojan.MSIL.Dropper.JB, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.MSIL.Dropper.JB?

Trojan.MSIL.Dropper.JB is a type of Trojan horse malware that can infect your computer without your knowledge or consent. The name "Trojan" refers to the malware's ability to disguise itself as a legitimate program or file, allowing it to bypass security measures and gain access to your system. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic language used by the .NET Framework. The "Dropper" term indicates that this malware is designed to drop or install additional malicious components on your system.

How Trojan.MSIL.Dropper.JB Operates

Trojan.MSIL.Dropper.JB operates by exploiting vulnerabilities in your system's security to gain unauthorized access. Once inside, it can drop additional malware components, such as viruses, worms, or spyware, which can cause further damage to your system. This malware can also communicate with its creators or other malicious servers to receive instructions or transmit stolen data. Its primary goal is to compromise your system's security and steal sensitive information, such as login credentials, financial data, or personal files.

Symptoms of Infection

Infected systems may exhibit various symptoms, including slow performance, frequent crashes, or unexpected behavior. You may notice unfamiliar programs or icons on your desktop, or receive suspicious pop-ups or alerts. In some cases, your antivirus software may detect and alert you to the presence of malware. However, Trojan.MSIL.Dropper.JB is designed to evade detection, so it's possible that your system may not display any obvious symptoms until it's too late.

How to Remove Trojan.MSIL.Dropper.JB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, which can detect and remove Trojan.MSIL.Dropper.JB and other malicious components.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed recently. This can help prevent the malware from spreading or reinstalling itself.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or add-ons that may be associated with the malware.
  5. Reboot your system and run a full scan with your anti-malware tool to ensure that all malicious components have been removed. Repeat this process until your system is clean and no further threats are detected.

Conclusion

Removing Trojan.MSIL.Dropper.JB from your system requires a combination of technical knowledge and the right tools. By following the steps outlined in this report, you can help protect your system from this and other types of malware. Remember to always be cautious when downloading software or clicking on links from unfamiliar sources, and keep your operating system and security software up to date to prevent future infections. If you're unsure about any aspect of the removal process, consider seeking the help of a professional or contacting a reputable security support service for assistance.

Analysis Report

General information

Family Name: Trojan.MSIL.Dropper.JB
Signature status: No Signature

Known Samples

MD5: b7464b2c1b56eb87265a4bcce5be0191
SHA1: 5e2c302f7be1bc3df470b04b37253a19cfc9a03a
SHA256: EDC129D27A2B4DE50AAD73F6685FC3E5C75744601EEC5AA197C67299C6B9B823
File Size: 45.06 KB, 45056 bytes
MD5: 54fe60e3a5d0c65765b1e1d5a1640a25
SHA1: c43886fb76acdb33b0101f2c6a7aaae279ca3d48
SHA256: F2304249142460E270B11989AD4E5534488A40C257E9D7EEC78A3627574A8094
File Size: 4.22 MB, 4219904 bytes
MD5: 67824ad8032fee6fd64a83ea2b1ded45
SHA1: d47a3e0c48b7a07f5e4e50479d200b84fe001a6a
SHA256: CB06827C809E5D41A022FD8232850CFBDCE485A8FFC36042AE48CA8FEECF6AE6
File Size: 351.74 KB, 351744 bytes
MD5: 22fc6161f68d491b11cd0bd9132a9928
SHA1: 39af0aeec6d30d4550b78239d82118dc431edde4
SHA256: 13F90141C4E084D12FA1F09E68B0D66CDF51A695D731766DCC2926C494B68DE7
File Size: 130.56 KB, 130560 bytes
MD5: 5983b270be5eb4b9edfdcbad5109f8c7
SHA1: b331f63164a42b7c6c262ec6d8eff7eaa083d5c2
SHA256: EE1470A93F9428233BEC41F737C627EFBEC5F9557FB53597AE8130BC610DFD6E
File Size: 4.22 MB, 4220416 bytes
Show More
MD5: e70de050197d7e091d12b10d0bd1e110
SHA1: df6de5e0a4dc319a8536a4ef39405af4ab727903
SHA256: 87EFD1BC8DA80080454C1B2E5BE226C94C886F883F10DB48C2E6F6FECF22FBAD
File Size: 135.74 KB, 135740 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.0.3.0
  • 1.8.0.0
  • 1.1.1.1
  • 1.0.0.0
Comments
  • dsfdsr rttre t ret re tre t re t re te r
  • Reparar BBDD SaDPe 3000
  • SaDPe Descarga de Actualizaciones
  • Suspends processes which are sending the WM_PALETTECHANGED message.
  • Time Attendance For G-Series
Company Name
  • Global App Software
  • HIP GLOBAL.Co.,Ltd
  • Macuyiko
  • Reparar BBDD SaDPe 3000
  • SaDPe SOFTWARE
File Description
  • HIP Premium Time
  • PalettestealerSuspender
  • RepararBBDD
  • SDPDowAct
  • ygyu uy f tyfit ryi
File Version
  • 2.0.4.21
  • 1.8.0.0
  • 1.1.1.1
  • 1.0.0.0
Internal Name
  • HIP Premium Time.exe
  • PalettestealerSuspender.exe
  • RepararBBDD.exe
  • SDPDowAct.exe
  • wawsw QWAWAE.exe
Legal Copyright
  • Copyright Global App Software © 2015
  • Copyright © 2009
  • Copyright © 2016
  • Copyright ©HIP GLOBAL.Co.,Ltd
  • Free For Use
Legal Trademarks ertrettretre r re t ert re t ert retretqqewqe qw e wqe wq e qw eq we
Original Filename
  • HIP Premium Time.exe
  • PalettestealerSuspender.exe
  • RepararBBDD.exe
  • SDPDowAct.exe
  • wawsw QWAWAE.exe
Product Name
  • HIP Premium Time
  • PalettestealerSuspender
  • Reparar BBDD SaDPe 3000
  • SDPDowAct
  • Software
Product Version
  • 2.0.4.21
  • 1.8.0.0
  • 1.1.1.1
  • 1.0.0.0

File Traits

  • .NET
  • .sdata
  • HighEntropy
  • NewLateBinding
  • ntdll
  • RijndaelManaged
  • Run
  • Stealer
  • x86

Block Information

Total Blocks: 198
Potentially Malicious Blocks: 28
Whitelisted Blocks: 170
Unknown Blocks: 0

Visual Map

x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.XGG
  • MSIL.Flooder.X
  • MSIL.HackAgent.RTA
  • MSIL.HackAgent.X
  • MSIL.NetSeal.A
Show More
  • MSIL.PSW.Agent.XC
  • MSIL.Stealer.EAE

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j�8��81��B �v y� xy �� �a ۀT�B�����1�����5����eeBx�<�� �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�-&�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��1�1HO1�D5�G6��9ߔ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data �ӹ��J�6+z��,��+z��Tg9_7��mw�������7Z���< |��3�0��J�4����4���lN����p�6/��O%\� RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 쐎ȳ耀렰쀆_鐄ȴ耀ᄟǛ鐄ȴ 鲱炻켜ʚ꺇뺶켜ʚ꺇뺶ګ켜ʚ꺇뺶켜ʚ릵犱쎫ʝ耀誙꣗ߦś洎ʫ赲荓㼁洎ʫ赲荓̚洎ʫ艄콘 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetThreadDesktop

1 additional items are not displayed above.

User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 860
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 852
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 816
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 760
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 844
Show More
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 756

Related Posts

Trending

Most Viewed

Loading...