Trojan

Should I remove “MSIL/TrojanDownloader.Agent.GGF”?

Malware Removal

The MSIL/TrojanDownloader.Agent.GGF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.GGF virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.GGF?


File Info:

name: 9C8193531B06F9E04B38.mlw
path: /opt/CAPEv2/storage/binaries/388f9a2180d3304e2df8987b26f15035da92a86c0f6262ab57c0dc4d036fd7d4
crc32: 637C07D0
md5: 9c8193531b06f9e04b38b013a774722e
sha1: 9ae7e9e35ad81b0e0d39de79eddb3b14fd6dcc85
sha256: 388f9a2180d3304e2df8987b26f15035da92a86c0f6262ab57c0dc4d036fd7d4
sha512: da499864806900d50d4e5cc01e17f5dc71c4001fa79e454f7eadec7d3edaf1dd1a0bae6b6862acd5164621e4cf4fa8c8c47ca3a357db99c4592766c9893c5e0d
ssdeep: 96:lMRRtYHdVeHPJprf+vv83VhZBTePgaYEWkeRFQIstZJo+OpMIU4kzNt:2RRCH3eHPjfz3NkeTQIs/G7vUv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19FF10904A3E84B37EDB94B7149B3D7505B79F703D933CA1E98CA021B5D22B506DA2B72
sha3_384: 4a0e2c83fb6e1e6872dab4bb3896cdf6936a908c1dbcbe90e93026eb6fd621cce6676bda78b3b3a86246fd7eaed07215
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-07-29 18:39:03

Version Info:

Translation: 0x0000 0x04b0
Comments: Google Chrome
CompanyName: Google Chrome
FileDescription: chome_exe
FileVersion: 67.0.100.99
InternalName: 111.exe
LegalCopyright: Copyright 2017 Google Inc. All rights reserved.
OriginalFilename: 111.exe
ProductName: Google Chrome
ProductVersion: 67.0.100.99
Assembly Version: 67.0.100.99

MSIL/TrojanDownloader.Agent.GGF also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.13574
FireEyeGeneric.mg.9c8193531b06f9e0
McAfeeArtemis!9C8193531B06
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Dotdo.d4bd529c
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
ArcabitIL:Trojan.MSILZilla.D3506
BitDefenderThetaGen:NN.ZemsilF.36196.am0@a4gTgFm
CyrenW32/MSIL_Downloader.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.GGF
APEXMalicious
CynetMalicious (score: 99)
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderIL:Trojan.MSILZilla.13574
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Trojan-Downloader.Ader.Gdhl
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1313700
VIPREIL:Trojan.MSILZilla.13574
TrendMicroTROJ_GEN.R002C0GBR23
McAfee-GW-EditionArtemis!Trojan
EmsisoftIL:Trojan.MSILZilla.13574 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1313700
Antiy-AVLTrojan[Downloader]/MSIL.Agent
XcitiumMalware@#2z0k2fsz3q057
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:Trojan.Multi.GenericML.xnet
GDataIL:Trojan.MSILZilla.13574
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.C4136159
ALYacIL:Trojan.MSILZilla.13574
MAXmalware (ai score=83)
MalwarebytesTrojan.PasswordStealer.MSIL
TrendMicro-HouseCallTROJ_GEN.R002C0GBR23
RisingTrojan.FakeChrome!1.9C7B (CLASSIC)
IkarusAdWare.Dotdo
MaxSecureTrojan.Malware.82199810.susgen
FortinetMSIL/Generic.AP.274570!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.31b06f
DeepInstinctMALICIOUS

How to remove MSIL/TrojanDownloader.Agent.GGF?

MSIL/TrojanDownloader.Agent.GGF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment