Trojan

MSIL/TrojanDownloader.Agent.EUJ (file analysis)

Malware Removal

The MSIL/TrojanDownloader.Agent.EUJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.EUJ virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.EUJ?


File Info:

name: 03FCA6A27F99F17C3AAE.mlw
path: /opt/CAPEv2/storage/binaries/249f18bef3edc11ced7a128a5e7247cbcc404a1dcd15fc67d51ccdf276d7895b
crc32: 60DE1964
md5: 03fca6a27f99f17c3aaebf3e766c9c28
sha1: 962af9ae35c2e552398e7b0acbcbe5d3cc50237b
sha256: 249f18bef3edc11ced7a128a5e7247cbcc404a1dcd15fc67d51ccdf276d7895b
sha512: f8b5c3f6c93f6f5a12b2bd5c621b82d9b0a781d03506e25fe2bbae02266ef62d9c13b17a4ad3f25e451516403ce4cc9b9cb2514fb8407492b0b7177b173e2911
ssdeep: 24576:NQP23SLHbz6ebr2wZ2+/PMS8R83mD0x1:NQ+cHXdiAvMS8qT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F31522C7926601BAC6E384BED1943B8E537C9BD150B8CC0F15A48A7BBC56F2B5B5402F
sha3_384: cb81815ba68c39d10f5036b051b27039847862c703c40b82c1aa781aea3df2a7db4197de69b2dcbc61fb199cf9415327
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-08-10 09:58:34

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: Encrypted.exe
LegalCopyright:
OriginalFilename: Encrypted.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.EUJ also known as:

BkavW32.Common.0336AD94
LionicTrojan.Win32.Zilla.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.19239
FireEyeGeneric.mg.03fca6a27f99f17c
ALYacIL:Trojan.MSILZilla.19239
Cylanceunsafe
VIPREIL:Trojan.MSILZilla.19239
SangforTrojan.Win32.Save.a
AlibabaTrojanDownloader:MSIL/AsyncRAT.15f1f82b
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36350.5m0@ayP6wfe
VirITTrojan.Win32.MSIL_Heur.A
CyrenW32/MSIL_Agent.ENH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.EUJ
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Orcus.gen
BitDefenderIL:Trojan.MSILZilla.19239
ViRobotTrojan.Win.Z.Agent.942592.G
AvastWin32:DropperX-gen [Drp]
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL2:4L6847NDi/PUowTJ4gZsHg)
EmsisoftIL:Trojan.MSILZilla.19239 (B)
F-SecureTrojan.TR/ATRAPS.Gen
TrendMicroTROJ_GEN.R002C0DHE23
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILZilla.19239
GoogleDetected
AviraTR/ATRAPS.Gen
ArcabitIL:Trojan.MSILZilla.D4B27
ZoneAlarmHEUR:Backdoor.MSIL.Orcus.gen
MicrosoftTrojanDownloader:MSIL/AsyncRAT.BJ!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RealProtect-LS.C5350023
Acronissuspicious
McAfeeArtemis!03FCA6A27F99
MAXmalware (ai score=84)
MalwarebytesBackdoor.Agent.PGen
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DHE23
TencentMsil.Trojan-Downloader.Ader.Gtgl
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AHHS!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.27f99f
DeepInstinctMALICIOUS

How to remove MSIL/TrojanDownloader.Agent.EUJ?

MSIL/TrojanDownloader.Agent.EUJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment