Malware

What is “MSIL/Agent.ATJ”?

Malware Removal

The MSIL/Agent.ATJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.ATJ virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine MSIL/Agent.ATJ?


File Info:

crc32: BC250AD5
md5: 9e26110cfee3f139617b6111c04f5111
name: 9E26110CFEE3F139617B6111C04F5111.mlw
sha1: adb53b79609714b516668b784b8e8d3840b33cdb
sha256: 8ec40ab1257e1cd720fced981679e9b76de55006d81050c4fffa0733fe9ee844
sha512: 0374eb093370826ef45e47ed555b4a88f6e2c1419019eef3c946ae3474dae39742d22b1f56bead81709422a2f2a41634e8702bc83c97dcea748572dda0a7eb16
ssdeep: 3072:PXsbuXa8ictRs4Fa1/J5JasJiCyW3SawPxKqB7ymLq+DYNCx7XAETdLbY:PAD/J5NxyWIKYe+DYNCJtb
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Example
Assembly Version: 1.0.0.0
InternalName: svchost.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Example
ProductVersion: 1.0.0.0
FileDescription: Example
OriginalFilename: svchost.exe

MSIL/Agent.ATJ also known as:

K7AntiVirusTrojan ( 005338bb1 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Ransom.PassCrypt.1
BitDefenderGen:Variant.Ransom.PassCrypt.1
K7GWTrojan ( 005338bb1 )
Cybereasonmalicious.cfee3f
CyrenW32/Trojan.DIS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.ATJ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:HackTool.MSIL.Flooder.gen
NANO-AntivirusTrojan.Win32.Ransom.fciwrg
MicroWorld-eScanGen:Variant.Ransom.PassCrypt.1
TencentMsil.Hacktool.Flooder.Hupi
Ad-AwareGen:Variant.Ransom.PassCrypt.1
SophosMal/Generic-S
ComodoMalware@#k01npjajehcy
BitDefenderThetaGen:NN.ZemsilF.34678.km0@aqHH@@f
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXGG-RH!9E26110CFEE3
FireEyeGeneric.mg.9e26110cfee3f139
EmsisoftGen:Variant.Ransom.PassCrypt.1 (B)
AviraHEUR/AGEN.1132421
eGambitUnsafe.AI_Score_99%
AegisLabHacktool.MSIL.Generic.3!c
ZoneAlarmHEUR:HackTool.MSIL.Flooder.gen
GDataGen:Variant.Ransom.PassCrypt.1
AhnLab-V3Trojan/Win32.Occamy.R230825
McAfeeGenericRXGG-RH!9E26110CFEE3
MAXmalware (ai score=98)
VBA32Trojan.MSIL.gen.a.1
RisingTrojan.Agent!8.B1E (CLOUD)
YandexTrojan.Agent!kAJ/w8bv520
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Generic.AP.14AC576!tr
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.Ransom.9dc

How to remove MSIL/Agent.ATJ?

MSIL/Agent.ATJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment