Trojan

How to remove “MSIL/TrojanDownloader.Agent.JSX”?

Malware Removal

The MSIL/TrojanDownloader.Agent.JSX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.JSX virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.JSX?


File Info:

name: A0BC6F188F4003AADF9F.mlw
path: /opt/CAPEv2/storage/binaries/9a472c5aef53c01e59c17c32f002fc718ac4d843c2b7636b28db379024af0796
crc32: 5C073E55
md5: a0bc6f188f4003aadf9f1faaffd5fb59
sha1: f3e2a7a1ceb81f0c5d1570817187772f9f2781e5
sha256: 9a472c5aef53c01e59c17c32f002fc718ac4d843c2b7636b28db379024af0796
sha512: 214681915af002397ad610aa60ee0cdee25d170bb326ec32ba6a4868d9afc62d67e0ea66e114c8111b46effb1d3a1ccbbbb888cc34347c2767a328adc83aa7c1
ssdeep: 1536:3Ks72Wwbl5VrCF/iZZZZZZZZZZZZZZZZZZZZZZZZcZZZZZZZZZZZZZZZZZZZJ9g8:6s72WwblzCF/P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12293D7CAAB117822CD2546B912F2C2B7D75B8D641172A24659FBFD2FBDF32023C63419
sha3_384: 9c0aa29e2f15fe734969f8b21bec434eb60efa36f3f0342a4859e2558d10673d7613499713101d7d36cafd0036f7c4e1
ep_bytes: ff250020400000000000000000000000
timestamp: 2095-07-20 23:21:20

Version Info:

Translation: 0x0000 0x04b0
Comments: FortiClient VPN Online Installation
CompanyName: Fortinet Inc.
FileDescription: FortiClient VPN Online Installation
FileVersion: 7.0.1.83
InternalName: cyber.exe
LegalCopyright: 2021 Fortinet Inc. All rights reserved.
LegalTrademarks:
OriginalFilename: cyber.exe
ProductName: FortiClient VPN Online Installation
ProductVersion: 7.0.1.83
Assembly Version: 7.0.1.83

MSIL/TrojanDownloader.Agent.JSX also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47598213
FireEyeGeneric.mg.a0bc6f188f4003aa
McAfeeGenericRXRB-PC!A0BC6F188F40
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 0058b6f71 )
AlibabaBackdoor:MSIL/Remcos.9a8952b3
K7GWTrojan-Downloader ( 0058b6f71 )
BitDefenderThetaGen:NN.ZemsilF.34084.fm0@aOMqL7g
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.JSX
TrendMicro-HouseCallTROJ_GEN.R002H0DL821
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
BitDefenderTrojan.GenericKD.47598213
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan-downloader.Agent.Llqy
Ad-AwareTrojan.GenericKD.47598213
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.47598213 (B)
IkarusTrojan-Spy.Vidar
GDataTrojan.GenericKD.47598213
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2D64A85
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4826892
ALYacTrojan.GenericKD.47598213
MalwarebytesTrojan.Downloader.MSIL.Generic
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.JRV!tr.dldr
WebrootW32.Trojan.Gen
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/TrojanDownloader.Agent.JSX?

MSIL/TrojanDownloader.Agent.JSX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment