Trojan

MSIL/TrojanDownloader.Agent.BUF removal

Malware Removal

The MSIL/TrojanDownloader.Agent.BUF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.BUF virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.BUF?


File Info:

name: F515B2EE42D6C0F4067E.mlw
path: /opt/CAPEv2/storage/binaries/12c025c4335bfd0e908bde16e70ad1d730d5f2ca20e1122925461e6197935042
crc32: 6E246D8D
md5: f515b2ee42d6c0f4067e0aea1572fcd9
sha1: 8f6e1eff4c27c1e20048866cc87406fba1f7c999
sha256: 12c025c4335bfd0e908bde16e70ad1d730d5f2ca20e1122925461e6197935042
sha512: 816c1646264e8a281bb5ba675adfa1094b2044e057fd0c0a1868580546801741f87fa5ea7fd1b0dc0aa4ab3ec38c5d4f6f582cd4c27c75c45d3d841530e0ddb3
ssdeep: 384:+fuqvV+2cdKlfEgUhaSJqVY7hoF7qs4IIwD1kLk24jXPlWuoy/wYZ65inWd:3YVyKZEjiVsI7DLIg1o2XP2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114D2092752DEBEE6C4B80670373343C1C36DEE045417DA2E99D4752AD9BE2437A927C8
sha3_384: 4f83910f57a781479558c15b3e9172dbd54a3017a3ad7b04e9551371c9c8b2c99b74df50cfcbb689e697cf90f90348d8
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-12-29 09:44:14

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: svchost
FileVersion: 1.0.0.0
InternalName: svchost.exe
LegalCopyright: Copyright © Microsoft 2017
OriginalFilename: svchost.exe
ProductName: svchost
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.BUF also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Heur.MSIL.Krypt.!cdmip!.2
ALYacGen:Heur.MSIL.Krypt.!cdmip!.2
MalwarebytesTrojan.Crypt.Generic
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:MSIL/Fsysna.07585f23
K7GWTrojan-Downloader ( 004eb7b11 )
K7AntiVirusTrojan-Downloader ( 004eb7b11 )
BitDefenderThetaGen:NN.ZemsilF.34712.bq0@a4cSFWp
CyrenW32/Trojan.CYO.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.BUF
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Fsysna.fplj
BitDefenderGen:Heur.MSIL.Krypt.!cdmip!.2
NANO-AntivirusTrojan.Win32.Fkm.ewohil
TencentWin32.Trojan-downloader.Generic.Eamn
Ad-AwareGen:Heur.MSIL.Krypt.!cdmip!.2
SophosMal/Generic-S
DrWebTrojan.DownloaderNET.223
ZillyaDownloader.Agent.Win32.348026
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f515b2ee42d6c0f4
EmsisoftGen:Heur.MSIL.Krypt.!cdmip!.2 (B)
APEXMalicious
AviraHEUR/AGEN.1204088
MAXmalware (ai score=97)
ArcabitTrojan.MSIL.Krypt.!cdmip!.2
GDataGen:Heur.MSIL.Krypt.!cdmip!.2
SentinelOneStatic AI – Malicious PE
AhnLab-V3Backdoor/Win32.Bladabindi.R216094
McAfeeArtemis!F515B2EE42D6
VBA32Trojan.MSIL.gen.a.1
PandaTrj/GdSda.A
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:luVoXVAB2L28oT0Y8eEnfw)
YandexTrojan.DL.Agent!lu4bw/o3Zyk
IkarusTrojan.Msil
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BUF!tr.dldr
AVGWin32:GenMaliciousA-VFO [Trj]
Cybereasonmalicious.e42d6c
AvastWin32:GenMaliciousA-VFO [Trj]

How to remove MSIL/TrojanDownloader.Agent.BUF?

MSIL/TrojanDownloader.Agent.BUF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment