Trojan

MSIL/TrojanDownloader.Agent.JSL (file analysis)

Malware Removal

The MSIL/TrojanDownloader.Agent.JSL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.JSL virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.JSL?


File Info:

name: D2070C2A18C4101FCBC2.mlw
path: /opt/CAPEv2/storage/binaries/fea4663e6f7e8357a9759efb66734e17ac8c821d1a0af38537b3ab9370cd895d
crc32: 30EB3F98
md5: d2070c2a18c4101fcbc261953a077b2e
sha1: 72bad37d58da047df743e7fdcaecd69b8fa1e927
sha256: fea4663e6f7e8357a9759efb66734e17ac8c821d1a0af38537b3ab9370cd895d
sha512: 376d4c10e436815bf1566a21adbf02151e2e9203c525bcded9e2cc15a2350a6fbbc82efe122ab86add805f0dd797ef4f4914bc9d53314c045a1fcfd138faea6a
ssdeep: 1536:5n9bv2ypa02beD+oPKjg7cMpdLVPZby1U/r3EVi6OXAhjv:l9bv2ypapkVFXq
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1EF64A09A9D321284F5154D73E5BBCBA8FB125EA467AC712B6E4C7430063317B2BAF131
sha3_384: 73344666ea9699e6aec649708570afab357e4103edf47c6e35e6abadcaa1bbad1b7fe6118a82b0100e30c99f9e96bda0
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2055-01-16 12:08:29

Version Info:

Translation: 0x0000 0x04b0
Comments: Foxit Reader Setup
CompanyName: Foxit Software Inc.
FileDescription: Foxit Reader Setup
FileVersion: 10.1.1.37576
InternalName: ConsoleApp12.exe
LegalCopyright: Copyright © 2004-2020 Foxit Software Inc. All Rights Reserved.
LegalTrademarks:
OriginalFilename: ConsoleApp12.exe
ProductName: Foxit Reader Setup
ProductVersion: 10.1.1.37576
Assembly Version: 10.1.1.37576

MSIL/TrojanDownloader.Agent.JSL also known as:

LionicTrojan.MSIL.Seraph.a!c
MicroWorld-eScanTrojan.GenericKD.47591306
FireEyeTrojan.GenericKD.47591306
McAfeeArtemis!D2070C2A18C4
SangforTrojan.MSIL.Seraph.gen
K7AntiVirusTrojan-Downloader ( 0058b7c91 )
AlibabaTrojanDownloader:MSIL/Lokibot.92707874
K7GWTrojan-Downloader ( 0058b7c91 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.JSL
TrendMicro-HouseCallTROJ_GEN.R002C0WLA21
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.MSIL.Seraph.gen
BitDefenderTrojan.GenericKD.47591306
AvastWin64:DropperX-gen [Drp]
Ad-AwareTrojan.GenericKD.47591306
EmsisoftTrojan.GenericKD.47591306 (B)
TrendMicroTROJ_GEN.R002C0WLA21
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusMalware.Win32.Injector
AviraTR/Dldr.Agent.tefwz
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:MSIL/Lokibot.EA!MTB
GDataTrojan.GenericKD.47591306
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Lokibot.C4856282
VBA32TrojanDownloader.MSIL.Seraph
ALYacTrojan.GenericKD.47591306
MAXmalware (ai score=86)
APEXMalicious
FortinetMSIL/Agent.JSL!tr.dldr
AVGWin64:DropperX-gen [Drp]
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/TrojanDownloader.Agent.JSL?

MSIL/TrojanDownloader.Agent.JSL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment