Trojan

MSIL/TrojanDownloader.Agent.HAG information

Malware Removal

The MSIL/TrojanDownloader.Agent.HAG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.HAG virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.HAG?


File Info:

name: 5C6EE32B1D381D0F902C.mlw
path: /opt/CAPEv2/storage/binaries/937359819abc03bcdf830a1d6ca4ce21a02a61f5278495410533fbe34dd60b86
crc32: D839DDEF
md5: 5c6ee32b1d381d0f902c076c75206410
sha1: 45f0b1ecc625c9128024f1b39d406434385b997b
sha256: 937359819abc03bcdf830a1d6ca4ce21a02a61f5278495410533fbe34dd60b86
sha512: fd2a67b2fec138b0a9601d7d7a9e5c68cae0088ba4db08d0bf556f114f58aacdba897b3719a1b6cce79b2fd125010b5a89b43eeeaaea6357a6707243dc781082
ssdeep: 768:o0Q1xp6sIRaxxeOy7C4yi66XjEyKXtItYcFwVc6K:oJZ6fRax0O4p6lyAtkwVcl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1C30F6AA3C8C026C465D275E412B4363B222CFB8875F2153D59B3576E72FE305CAB1B
sha3_384: 41287354e4ec97b12da1aa2a3e9536536cf0c17dd36a85ac2c77fc7adc27657b0bda348cb88a93ef7a3462ce971c0f48
ep_bytes: ff250020400000000000000000000000
timestamp: 2056-02-14 20:35:46

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: launcher2.0
FileVersion: 1.0.0.0
InternalName: DCQPKX.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: DCQPKX.exe
ProductName: launcher2.0
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.HAG also known as:

Elasticmalicious (high confidence)
ClamAVWin.Packed.Bulz-9831654-0
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Heur.Variadic.A.173.1
MalwarebytesRansom.Black
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CyrenW32/FakeDoc.AQ.gen!Eldorado
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HAG
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Heur.Variadic.A.173.1
MicroWorld-eScanGen:Heur.Variadic.A.173.1
RisingRansom.Agent!1.CE85 (CLASSIC)
Ad-AwareGen:Heur.Variadic.A.173.1
EmsisoftGen:Heur.Variadic.A.173.1 (B)
FireEyeGeneric.mg.5c6ee32b1d381d0f
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.Variadic.A.173.1
AviraHEUR/AGEN.1209660
ArcabitTrojan.Variadic.A.173.1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Gen.RL_Reputation.C4345418
McAfeeGenericRXAA-FA!5C6EE32B1D38
MAXmalware (ai score=86)
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.HGV!tr.ransom
BitDefenderThetaGen:NN.ZemsilF.34182.hm0@aS9RGcg
Cybereasonmalicious.b1d381

How to remove MSIL/TrojanDownloader.Agent.HAG?

MSIL/TrojanDownloader.Agent.HAG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment