Trojan

MSIL/TrojanDownloader.Agent.HNR removal instruction

Malware Removal

The MSIL/TrojanDownloader.Agent.HNR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.HNR virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.HNR?


File Info:

name: E503F664DBAF39BB241D.mlw
path: /opt/CAPEv2/storage/binaries/f2fdfdf10ddab4d8c0521967facf3e07f5877afb8de65e1253b5636b5e296939
crc32: 00EFAEC0
md5: e503f664dbaf39bb241dc11ffac66cbc
sha1: 741b3c6fa404013d45838df364045d81e3453738
sha256: f2fdfdf10ddab4d8c0521967facf3e07f5877afb8de65e1253b5636b5e296939
sha512: 4c0f89898e0b8ce88b8890ea34b8cb7eb941ddde1db3b08a73ad1813f5a48b06633dab3e2463861d9b7795af163d8f9622e567dd8195ff260adeced4d480ec07
ssdeep: 1536:lb3Olm1QE2Hzh7vU4yKkYPAEBpbncvwXnrEAz6oUKXPOF93hUwoczXZoXkAtmXd8:lb3Olm2bHzh7U4yKkYPAEBpbncvwXnrv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E77393EAB9847E56EECC7D329C01A23DD10C58AC3A1167440B8CB7AD65762B48EDFD0D
sha3_384: ce59d66cf07b78a03c81a9406fe69d09b0c9b3b229e97daaee7b347003ebae508259945e64a1f09eb5ea514605cceab0
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-01-21 11:40:51

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: hkUE
FileVersion: 1.0.0.0
InternalName: hkUE.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: hkUE.exe
ProductName: hkUE
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.HNR also known as:

LionicTrojan.Win32.Generic.4!c
McAfeeArtemis!E503F664DBAF
MalwarebytesTrojan.Downloader.MSIL.Generic
SangforTrojan.Win32.Zpevdo.B
Cybereasonmalicious.fa4040
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HNR
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AvastWin32:TrojanX-gen [Trj]
DrWebTrojan.DownloaderNET.178
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.e503f664dbaf39bb
SophosGeneric ML PUA (PUA)
IkarusTrojan-Downloader.MSIL.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZemsilF.34606.em0@aiAxdYk
CylanceUnsafe
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:jKP2Zro5Lj1ZT8TJSTzu+g)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.HNR!tr.dldr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove MSIL/TrojanDownloader.Agent.HNR?

MSIL/TrojanDownloader.Agent.HNR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment