Malware

MSIL/Agent.THK removal tips

Malware Removal

The MSIL/Agent.THK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.THK virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/Agent.THK?


File Info:

name: 2D25B972AFEFCF755F6B.mlw
path: /opt/CAPEv2/storage/binaries/f9ab8e7fe0b9623b555f8e4517657a8214889bbe16cb147185347bf84b630e4b
crc32: 0CC72E4C
md5: 2d25b972afefcf755f6b7d40b24d0a92
sha1: f1f2d97742aa7d3d1c1d88a019136572ae9139c8
sha256: f9ab8e7fe0b9623b555f8e4517657a8214889bbe16cb147185347bf84b630e4b
sha512: 1a7b159074086d2bb80b5ca529d2e15efaae40d9e4dee128eb81788edca54702f94818243c5cc85e657b8486faf088b9fb5a8b446b58f85594aeecb7d958a244
ssdeep: 6144:TN0KJM8wfYwSnsXFC0yxv470md6CfSd9SGg/sF/HyQhLOk9pw7WfNi89GISJ3X:u98wfn8s1ewjkCfTd/sR9rJiaGv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D74230173DF9331CA24833C7B7A568A7A86E7584986D2871B3482FF7A0B76F06549D3
sha3_384: 7ec244130299d25ebcb0727bc88d78b6a09311290333c965538dd6f848efaa2ae27a28cc97d6c4f0ce997497fb118f18
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-07-10 21:37:50

Version Info:

Translation: 0x0000 0x04b0
Comments: Windows File Management Optimizer
CompanyName: Microsoft Corporation
FileDescription: Windows Explorer
FileVersion: 1.0.0.0
InternalName: Windows Explorer.exe
LegalCopyright: 8F89C700040F900C
LegalTrademarks:
OriginalFilename: Windows Explorer.exe
ProductName: Windows Explorer
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Agent.THK also known as:

LionicTrojan.Win32.Xploder.i!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop10.1110
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
FireEyeGeneric.mg.2d25b972afefcf75
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeGenericRXIJ-RP!2D25B972AFEF
CylanceUnsafe
ZillyaTrojan.Redcap.Win32.5
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanPSW:Win32/Xploder.07606764
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2afefc
BitDefenderThetaGen:NN.ZemsilF.34182.vm0@aacCD0i
CyrenW32/MSIL_Kryptik.FKA.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32MSIL/Agent.THK
TrendMicro-HouseCallTROJ_GEN.R002C0DL421
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Xploder.u
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.Xploder.ipxypi
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10cf8460
Ad-AwareGen:Heur.MSIL.Bladabindi.1
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DL421
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.MSIL.Bladabindi.1
JiangminTrojan.MSIL.mxtl
AviraTR/Agent.etoyb
MAXmalware (ai score=85)
Antiy-AVLTrojan/MSIL.Dnoper
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.MSIL.Bladabindi.1
ZoneAlarmTrojan-PSW.Win32.Xploder.u
MicrosoftTrojan:Win32/Wacatac.B!rfn
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Agent.C4084289
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Bot
APEXMalicious
YandexTrojan.PWS.Xploder!1X0q5EptakU
IkarusPUA.MSIL.Confuser
MaxSecureTrojan.Malware.1728101.susgen
FortinetRiskware/Xploder
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove MSIL/Agent.THK?

MSIL/Agent.THK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment