Threat Database Trojans Trojan.MSIL.Injector.TG

Trojan.MSIL.Injector.TG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,220
Threat Level: 80 % (High)
Infected Computers: 363
First Seen: March 5, 2023
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Injector.TG on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system. It's crucial to address this issue promptly to prevent further damage to your computer and protect your personal data.

What Is Trojan.MSIL.Injector.TG?

Trojan.MSIL.Injector.TG is identified as a Trojan-type threat. Trojans are malicious programs that can allow unauthorized access to a computer, leading to a variety of harmful activities. They are often disguised as legitimate software, making them difficult to detect without proper security measures. The name "Trojan.MSIL.Injector.TG" suggests it may involve code injection techniques, potentially allowing it to evade detection by traditional security software or to install additional malware.

How Trojan.MSIL.Injector.TG Operates

While specific details about how Trojan.MSIL.Injector.TG operates are not available, Trojans generally work by exploiting vulnerabilities in software or manipulating users into installing them. Once installed, they can create backdoors, allowing remote access to the infected computer. This access can be used for various malicious purposes, including data theft, installation of additional malware, or using the computer as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely, depending on the specific goals of the malware. Common indicators include unusual system behavior, such as unexpected crashes, slow performance, or unfamiliar programs and icons. You might also notice increased network activity, even when you're not using the internet, or find that your security software is disabled. Sometimes, Trojans can operate silently, making them harder to detect without regular system scans.

How to Remove Trojan.MSIL.Injector.TG

  1. Boot into Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. To do this, restart your computer and repeatedly press the F8 key as it boots up. Select "Safe Mode with Networking" from the Advanced Boot Options menu.
  2. Perform a Full Scan with a Reputable Tool: Use an anti-malware tool like SpyHunter to scan your system thoroughly. Ensure the tool is updated with the latest definitions before scanning to increase the chances of detecting and removing the Trojan.
  3. Uninstall Suspicious Programs: Go through your list of installed programs and remove any that you don't recognize or that were installed around the time the Trojan was detected.
  4. Reset Your Browser: Trojans can sometimes install malicious extensions or alter browser settings. Resetting browsers like Chrome, Firefox, or Edge to their default settings can help remove these changes. You can find this option in the settings or preferences menu of each browser.
  5. Reboot and Re-scan: After removal and cleanup, restart your computer in normal mode and perform another scan with your anti-malware tool to ensure all traces of the Trojan have been removed.

Conclusion

Removing Trojan.MSIL.Injector.TG requires a combination of using the right tools, understanding how Trojans operate, and taking preventive measures to avoid future infections. By following the steps outlined in this report and maintaining good cybersecurity practices, such as regularly updating your software and being cautious with email attachments and downloads, you can significantly reduce the risk of malware infections. Remember, vigilance and proactive security measures are key to protecting your digital environment.

Analysis Report

General information

Family Name: Trojan.MSIL.Injector.TG
Signature status: Self Signed

Known Samples

MD5: 2ee41db758fd06587bc49de9ce4f78f0
SHA1: 5ea0f8ddc88ff762edaec13591746860cc10d132
SHA256: C11F220FB1368BB3583716C94EDEB2FBEA8FE0BA446B32CB310ECE791EA47248
File Size: 3.23 MB, 3226624 bytes
MD5: 6013ebb59fd23ec77012faf09cfa00c5
SHA1: fc4dd1d7b3c4fd0291e7222487e2ec0069e89fd3
SHA256: B44927129C3809E07CCFDE6D7C87D83A1076C038B0EAFB7AADF279D5397E9C00
File Size: 2.75 MB, 2748416 bytes
MD5: aa2a58f6f736c72fb2c45c2710c69e32
SHA1: c658313de7d7fc323b5518b56a6087456dc06712
SHA256: 0DC035849B11C9001D1788C165E17567DB6DC6B96F74FFA71F5F9A15063FCC7A
File Size: 6.02 MB, 6016376 bytes
MD5: fac43a417ca80e0073a167f0d6ba022d
SHA1: ec4f463f610a9c09061222ec3b67916bab246707
SHA256: 18E9906B5B49580EDFF17AC56F41C8D8680E55F7BC8F373DC2546BD8D3E17FF5
File Size: 6.03 MB, 6028528 bytes
MD5: fd3d40ee35b36f70e4698e343af1e7bb
SHA1: cb10b049b5674b9fa8558a2ed6afb4e58459ce29
SHA256: 0C4F06709A8A3762D8622D290BA35819B36909F88F93C2DDCE5BFE48F6F7CC2E
File Size: 6.29 MB, 6285040 bytes
Show More
MD5: 4c34986e4f560b972239fd1ceb11be0b
SHA1: e28aa60f44b3953b35d4a84d053f9d7a480b9974
SHA256: 86D3A86F82F675F29B4B07C0C73D5B7CD000CEC91B4BCB7C51A8831E8AD51E2F
File Size: 6.28 MB, 6279920 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.4.1.8
  • 2.0.0.0
  • 1.0.4.0
Comments
  • OldSkools ProMod
  • Sistema de Gerenciamento Empresarial
Company Name
  • Gateway Sistemas
  • OldSkools ProMod
File Description
  • Gateway
  • GodofWar +27 Trainer by DNA
  • OldSkools ProMod for WoT
File Version
  • 2.4.1.9
  • 2.0.0.0
  • 1.0.4.0
Internal Name
  • Gateway.exe
  • GodofWar.exe
  • ProMod.exe
Legal Copyright
  • Copyright © 2021
  • Copyright © Gateway 2020
  • OldSkools ProMod
Legal Trademarks OldSkools ProMod
Original Filename
  • Gateway.exe
  • GodofWar.exe
  • ProMod.exe
Product Name
  • Gateway
  • Home of Gamehacking
  • OldSkools ProMod
Product Version
  • 2.4.1.9
  • 2.0.0.0
  • 1.0.4.0

Digital Signatures

Signer Root Status
OldSkoolsProMod OldSkoolsProMod Self Signed

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • VirtualQueryEx
  • WriteProcessMemory
  • x64
  • x86

Block Information

Total Blocks: 2,972
Potentially Malicious Blocks: 161
Whitelisted Blocks: 2,367
Unknown Blocks: 444

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? x ? ? ? ? ? ? 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? x 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 ? ? ? ? ? 0 0 ? 0 0 0 0 ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 x x 0 ? ? ? 0 ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 x x 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 0 x x x x 0 0 0 x 0 x 0 x 0 x ? x 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 x x ? x 0 0 x 0 x 0 0 0 x 0 x x 0 0 0 x 0 x x x 0 x x x x x x 0 0 x 0 x x 0 0 0 x x x x x x x 0 0 0 0 0 0 x x x x 0 0 0 x 0 x 0 x ? ? x x 0 0 0 0 x x 0 x 0 x x x x x 0 x ? x x 0 x 0 0 x 0 x 0 x x 0 0 x x x x 0 0 0 x 0 0 x x x 0 0 0 0 x x x x x x x 0 x 0 0 0 x 0 x x x 0 0 0 0 x x x x x x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 x x x x x x 0 0 x 0 0 0 0 0 ? 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? ? 0 ? ? ? 0 ? ? 0 ? 0 ? 0 0 0 ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...