Malware

MSIL/Agent.KH (file analysis)

Malware Removal

The MSIL/Agent.KH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.KH virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Agent.KH?


File Info:

name: 19F3550D80E683F847D7.mlw
path: /opt/CAPEv2/storage/binaries/d9a0e703e27727959faf93693ead47e46d84162e744e8f6b2d66a7a6dec8375d
crc32: 96C98B63
md5: 19f3550d80e683f847d7accf2583b6b2
sha1: 848b7f2417c4332e73a91033964e3a1d35f963b9
sha256: d9a0e703e27727959faf93693ead47e46d84162e744e8f6b2d66a7a6dec8375d
sha512: 6e703fa357780b72d3f2e80dbb728b7048ad02e5e2c3f7df5184e696745886862a5fdb4171cfee9cc35606b36766fed3a2c78e85edf8d8fc55080e6707857692
ssdeep: 768:OHj6Am1dW5r/gd/CLc01dqEvDlCWZne97ZxuEW6XGKujURa2dME:OD6AmG1e/CLL1dqEvnZo7ZvZ7kURaIP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C233B1877E98618F1BF6FBA0E70668507B5FD125217E62D0ED460AB5A73B50CF02B32
sha3_384: d5f0316189246d3926c34ee55692c5d9bf6fe12483171aee6553419095bed64512ec47f5af621bca27c1b286063338ce
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-04-25 17:54:48

Version Info:

Translation: 0x0000 0x04b0
Comments: help keep all Windows systems file secure and to provide the latest features and improvements.
CompanyName: Microsoft Corporation.
FileDescription: Windows Update Assistant
FileVersion: 10.0.17134.1
InternalName: E.exe
LegalCopyright: Microsoft Corporation. All rights reserved ©
OriginalFilename: E.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Assembly Version: 10.0.17134.1

MSIL/Agent.KH also known as:

LionicTrojan.Win32.Fsysna.4!c
DrWebTrojan.DownLoader27.27812
MicroWorld-eScanIL:Trojan.MSILMamut.6403
FireEyeGeneric.mg.19f3550d80e683f8
McAfeeGenericRXHN-LW!19F3550D80E6
Cylanceunsafe
ZillyaTrojan.Fsysna.Win32.17787
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056fb7f1 )
AlibabaBackdoor:MSIL/Bladabindi.f9805928
K7GWTrojan ( 0056fb7f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36318.dm0@auX@iPc
VirITTrojan.Win32.MSIL_Heur.A
CyrenW32/ABRisk.NEHX-4740
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.KH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Fsysna.gen
BitDefenderIL:Trojan.MSILMamut.6403
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Bladabindi.16000442
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1305686
VIPREIL:Trojan.MSILMamut.6403
TrendMicroTROJ_GEN.R002C0DDP23
McAfee-GW-EditionGenericRXHN-LW!19F3550D80E6
Trapminemalicious.moderate.ml.score
EmsisoftIL:Trojan.MSILMamut.6403 (B)
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILMamut.6403
JiangminTrojan.MSIL.meql
AviraHEUR/AGEN.1305686
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi
ArcabitIL:Trojan.MSILMamut.D1903
ZoneAlarmHEUR:Trojan.MSIL.Fsysna.gen
MicrosoftBackdoor:MSIL/Bladabindi.G
GoogleDetected
AhnLab-V3Trojan/Win32.Disfa.C209087
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacIL:Trojan.MSILMamut.6403
MAXmalware (ai score=86)
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DDP23
RisingBackdoor.Bladabindi!8.B1F (CLOUD)
YandexTrojan.Fsysna!nKmKcaOVrLU
IkarusTrojan-Dropper.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.KH!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.d80e68
DeepInstinctMALICIOUS

How to remove MSIL/Agent.KH?

MSIL/Agent.KH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment