Trojan

About “MSIL/TrojanDownloader.Agent.JRM” infection

Malware Removal

The MSIL/TrojanDownloader.Agent.JRM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.JRM virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.JRM?


File Info:

name: 7A01EC21D2551A474771.mlw
path: /opt/CAPEv2/storage/binaries/322a2416207ad49665bdceac4cce96b536f96364874af1283224de52abfa89ca
crc32: 9BFA2C70
md5: 7a01ec21d2551a474771797242ae57f5
sha1: 44232bd9a5f73c963752ae168da990ce14a6b226
sha256: 322a2416207ad49665bdceac4cce96b536f96364874af1283224de52abfa89ca
sha512: 535ae42e3e6496b3fa33404577a9ea74f9467a65d84ed74a60c59751118da10deeb52a9af486e37a54727810512b4eb9db99412d5d416e86af1cc321c82f5143
ssdeep: 192:TQbnCBZuStKXjN7Uyc8Q7MkY5vS8p5xV6MWLXSgI7F2SNPA:kL0Z6Te5akYc8FQFXSgIpTP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142522A85BBE48A16D9BE89FB9C3356048775FB1B9802DF5D29CC60EB6D037804F00B66
sha3_384: c6f3532ad748ecd2273dd51fad851c4009c7e613bfc8a2b73a4e152132f12194d59564a80397b666873129b072e8b4ea
ep_bytes: ff250020400041004200430044004500
timestamp: 2080-07-26 05:07:34

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ApolonSpaceXLoader
FileVersion: 1.0.0.0
InternalName: ApolonSpaceXLoader.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: ApolonSpaceXLoader.exe
ProductName: ApolonSpaceXLoader
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.JRM also known as:

LionicTrojan.MSIL.Startun.4!c
DrWebTrojan.DownloaderNET.204
MicroWorld-eScanTrojan.GenericKD.47567632
FireEyeGeneric.mg.7a01ec21d2551a47
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0058b6431 )
AlibabaTrojan:MSIL/Startun.853259d4
K7GWTrojan-Downloader ( 0058b6431 )
BitDefenderThetaGen:NN.ZemsilF.34062.am0@a4tOKJm
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.JRM
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Startun.gen
BitDefenderTrojan.GenericKD.47567632
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan.Startun.Agkv
Ad-AwareTrojan.GenericKD.47567632
SophosMal/Generic-S
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftTrojan.GenericKD.47567632 (B)
IkarusTrojan-Downloader.MSIL.Agent
GDataTrojan.GenericKD.47567632
JiangminTrojan.MSIL.alouh
AviraTR/Dldr.Agent.qfpwr
Antiy-AVLTrojan/Generic.ASMalwS.34E47DF
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4814589
ALYacTrojan.GenericKD.47567632
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R002H07L521
YandexTrojan.Startun!kFgpDjhgAJs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.JRM!tr.dldr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDownloader.Agent.JRM?

MSIL/TrojanDownloader.Agent.JRM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment