Malware

MSIL/Agent.DZK (file analysis)

Malware Removal

The MSIL/Agent.DZK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.DZK virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine MSIL/Agent.DZK?


File Info:

name: 40EB4FA08A7502F32171.mlw
path: /opt/CAPEv2/storage/binaries/f5a20b66edc5ddc4a56a6f7342a320a39908b69b6ef65ff5f9abd10d7fb8ffd7
crc32: CB1A9F3E
md5: 40eb4fa08a7502f321711fd0011dc94c
sha1: acdc1efd7d9e1f5d27223faaa4760ec178247bd0
sha256: f5a20b66edc5ddc4a56a6f7342a320a39908b69b6ef65ff5f9abd10d7fb8ffd7
sha512: a81798b8df7de59b47ce99c29be48d8cd1be1ec9e383e28086cc4ad5b3f93d8dccb48a7295590473803788c408e31ec2e6230f10b8d320dfc022ea245f80bbe6
ssdeep: 1536:LAjKFc6C35Qwi2TZPOnqc+Jp86beyU0gDwrH3iF3:LNi35dAnqcOe6U0gDwrH3W3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12973085823E5663ADCAF69F0297AD95421F01EA7C9BDC38D6BE58E741F112D18F000BB
sha3_384: e27a6030a4ed000a8181c530ab2d92ccdf32f3939efca7a9964c514d46356a47317658c04ecca6453bb3f509bcd6a80c
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-14 18:16:35

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: XWormClient.exe
LegalCopyright:
OriginalFilename: XWormClient.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Agent.DZK also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
McAfeeArtemis!40EB4FA08A75
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059553f1 )
K7GWTrojan ( 0059553f1 )
Cybereasonmalicious.d7d9e1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.DZK
APEXMalicious
KasperskyUDS:Trojan.Win32.GenericML.xnet
F-SecureTrojan.TR/ATRAPS.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.40eb4fa08a7502f3
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
GDataWin32.Trojan.Agent.IIXQVX
Acronissuspicious
VBA32CIL.StupidPInvoker-1.Heur
TrendMicro-HouseCallTROJ_GEN.R014H0AGS22
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:tgb7MLgksbtzFUFOpSjzKA)
IkarusHackTool.Win32.BruteForce
FortinetMSIL/Agent.DZK!tr
BitDefenderThetaGen:NN.ZemsilF.34806.em0@aOlaPQh
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Agent.DZK?

MSIL/Agent.DZK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment