Trojan

What is “MSIL/TrojanDownloader.Agent.GYM”?

Malware Removal

The MSIL/TrojanDownloader.Agent.GYM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.GYM virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/TrojanDownloader.Agent.GYM?


File Info:

crc32: 3DD316DA
md5: d3dd64a09b7e6d23b49e7cfa0dcc7a1f
name: upload_file
sha1: cd197ffaa8a933d304b2f6f208a4a805ada97190
sha256: b6138f3435c7c4049fa524e698b6d167b09f6105572931a94b92759cffddd8d6
sha512: 43ee4a7ad3d145b6db6305a1d19311231bcce98b76eec60f658cfbd8ccaa1d8d557cb7232003428c76e041d03aa9045e6b49c38d6c7e03bf4009712304f4fb94
ssdeep: 768:XopLoQ4j42om3Y4oPhgZEUQ4idwA/+A8C7QAx1NszPbZVsaoKSLyhyFx5rQj3rvR:MLoXnp3SsXwTXPb8dBNHh9HrCzUf/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 x5f17x5f17x5f17. All rights reserved.
Assembly Version: 3.1.8.8
FileVersion: 0.4.0.3
CompanyName: x543ex543ex543e
LegalTrademarks: x543ex543ex543e
Comments: x5f17x5f17x5f17 x5f17x5f17x5f17
ProductName: x543ex543ex543e x5f17x5f17x5f17
ProductVersion: 3.1.8.8
FileDescription: x543ex543ex543e x5f17x5f17x5f17
OriginalFilename: x543ex543ex543e x5f17x5f17x5f17.exe
Translation: 0x0409 0x0514

MSIL/TrojanDownloader.Agent.GYM also known as:

MicroWorld-eScanTrojan.GenericKD.34877929
FireEyeGeneric.mg.d3dd64a09b7e6d23
CAT-QuickHealTrojan.Wacatac
McAfeeRDN/GenericM
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 00570f721 )
BitDefenderTrojan.GenericKD.34877929
K7GWTrojan-Downloader ( 00570f721 )
TrendMicroTROJ_GEN.R03BC0PJS20
BitDefenderThetaGen:NN.ZemsilF.34590.fm1@aWvCIEhi
CyrenW32/MSIL_Kryptik.BXZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DangerousSig [Trj]
AlibabaTrojan:MSIL/DangerousSig.80a7b663
Ad-AwareTrojan.GenericKD.34877929
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Agent.epola
InvinceaMal/Generic-S
McAfee-GW-EditionRDN/GenericM
EmsisoftTrojan.GenericKD.34877929 (B)
SentinelOneDFI – Malicious PE
AviraTR/Dldr.Agent.epola
Antiy-AVLTrojan[Downloader]/MSIL.Agent
ArcabitTrojan.Generic.D21431E9
GDataTrojan.GenericKD.34877929
ALYacTrojan.GenericKD.34877929
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GZ.Generic
PandaTrj/GdSda.A
ZonerTrojan.Win32.96570
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.GYM
TrendMicro-HouseCallTROJ_GEN.R03BC0PJS20
TencentMsil.Trojan-downloader.Agent.Wskb
YandexTrojan.Igent.bUGcPa.29
IkarusTrojan.MSIL.Inject
FortinetMSIL/Agent.GWR!tr.dldr
AVGWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Generic/Trojan.d93

How to remove MSIL/TrojanDownloader.Agent.GYM?

MSIL/TrojanDownloader.Agent.GYM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment