Trojan

MSIL/TrojanDownloader.Agent.GKO removal guide

Malware Removal

The MSIL/TrojanDownloader.Agent.GKO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.GKO virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/TrojanDownloader.Agent.GKO?


File Info:

crc32: 4C75F876
md5: fa7d042c73d3711b3c22e13f809fb4b9
name: FA7D042C73D3711B3C22E13F809FB4B9.mlw
sha1: 704f65e3137484df20864b5a0f53563a2eb23d05
sha256: c339732e7107fb8b1f7e8c8c84ef68601d57daad92cf53eee5d03ec53b59b0e0
sha512: f571460c45631941e4fd592f618808b7d0dd8a13a421b6fb0d5ab778201f396019bb0453cef171474edd5203b15d0168b9f92d6a638c51b51711cea57d5e8360
ssdeep: 384:nYi6JTDyZDnLjUTsuuG+JJfneR9T1M+vganE51AZYa2dpI9ZjlyOikFTJZ2gX60:Yi48vUjue+iE5sBVkQrSOHHp
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright DarthOCE xa9 2021
Assembly Version: 1.0.0.0
InternalName: sProxy.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: sProxy
ProductVersion: 1.0.0.0
FileDescription: sProxy
OriginalFilename: sProxy.exe

MSIL/TrojanDownloader.Agent.GKO also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.MSILHeracles.1177
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.c73d37
CyrenW32/MSIL_Troj.AGQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.GKO
APEXMalicious
AvastWin32:DropperX-gen [Drp]
BitDefenderGen:Variant.MSILHeracles.1177
MicroWorld-eScanGen:Variant.MSILHeracles.1177
Ad-AwareGen:Variant.MSILHeracles.1177
McAfee-GW-EditionPWS-FCZI!FA7D042C73D3
FireEyeGeneric.mg.fa7d042c73d3711b
EmsisoftGen:Variant.MSILHeracles.1177 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1139408
Antiy-AVLTrojan/Generic.ASMalwS.34BF860
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.MSILHeracles.D499
GDataGen:Variant.MSILHeracles.1177
AhnLab-V3Trojan/Win32.Agent.R339807
McAfeePWS-FCZI!FA7D042C73D3
MAXmalware (ai score=86)
MalwarebytesTrojan.Downloader
YandexTrojan.DL.Agent!BDicKmfHPMs
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/TrojanDownloader.AGENT.GIQ!tr
AVGWin32:DropperX-gen [Drp]

How to remove MSIL/TrojanDownloader.Agent.GKO?

MSIL/TrojanDownloader.Agent.GKO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment