Trojan

MSIL/TrojanDownloader.Agent.JYI removal instruction

Malware Removal

The MSIL/TrojanDownloader.Agent.JYI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.JYI virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.JYI?


File Info:

name: 1823B9B5F5EB2B3485E1.mlw
path: /opt/CAPEv2/storage/binaries/449cf1a8817453ad29c0d5e68021c64344a9a2bab6c6113c1df7f08181d2e6c2
crc32: 464C4A53
md5: 1823b9b5f5eb2b3485e1015a7d05fc17
sha1: 5b12b7f38b1588bc7f3f825de3a5c21fdfdec38f
sha256: 449cf1a8817453ad29c0d5e68021c64344a9a2bab6c6113c1df7f08181d2e6c2
sha512: 06167800269e29f0009f3009f289ab2289c9f6d5e24cae07ba512d193fc1274f3c017f6efe39b90f59dd47a5aec702ed94261136a01f98e6acb58e02dfee9613
ssdeep: 6144:04Yx9yEeqmvxqd6YOp9NgHJZ0EQOJ93p6L:HYreJvA6YODNWGwf6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12144D082B404A2D0F5684A32D557DAB40627BE77AE04BD4F3094FF8736733D36626B4A
sha3_384: 0ffca0efcdec8384015a6cebf286a3a4453d5a64cbfda797fb5005490c8c3686d4ea20a7ac5b8e8f603a5ccfefd2d05d
ep_bytes: ff250020400000000000000000000000
timestamp: 2071-10-11 03:28:49

Version Info:

Translation: 0x0000 0x04b0
Comments: MetaEditor
CompanyName: MetaQuotes Ltd.
FileDescription: MetaEditor
FileVersion: 5.0.0.2395
InternalName: Dripler.exe
LegalCopyright: © 2000-2021, MetaQuotes Ltd.
LegalTrademarks: MetaTrader
OriginalFilename: Dripler.exe
ProductName: MetaQuotes Language 5 Editor
ProductVersion: 5.0.0.2395
Assembly Version: 5.0.0.2395

MSIL/TrojanDownloader.Agent.JYI also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Stealer.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38490822
FireEyeGeneric.mg.1823b9b5f5eb2b34
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeRDN/RedLineStealer
CylanceUnsafe
ZillyaDownloader.Agent.Win32.460365
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0058ce381 )
AlibabaTrojanSpy:MSIL/Stealer.a3209694
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Kryptik.GUW.gen!Eldorado
SymantecMSIL.Downloader!gen8
tehtrisGeneric.Malware
ESET-NOD32MSIL/TrojanDownloader.Agent.JYI
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.GenericKD.38490822
NANO-AntivirusTrojan.Win32.Stealer.jnlthx
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan-downloader.Agent.Dwtf
Ad-AwareTrojan.GenericKD.38490822
ComodoMalware@#2swftvv82hw34
DrWebTrojan.PWS.Steam.24014
VIPRETrojan.GenericKD.38490822
TrendMicroTROJ_FRS.0NA103AC22
McAfee-GW-EditionRDN/RedLineStealer
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.38490822 (B)
IkarusTrojan-Downloader.MSIL.Agent
GDataTrojan.GenericKD.38490822
JiangminTrojanSpy.MSIL.cdph
WebrootW32.Trojan.MSIL.AGensla
AviraTR/Dldr.Agent.jpmvs
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.1B9
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D24B52C6
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C4909200
Acronissuspicious
VBA32TrojanSpy.MSIL.Stealer
ALYacTrojan.GenericKD.38490822
MalwarebytesTrojan.Downloader.MSIL.Generic
TrendMicro-HouseCallTROJ_FRS.0NA103AC22
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:rdYv1Ezh0kvwoLpR8hPwng)
YandexTrojan.DL.Agent!A3nYtyRp5uY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.JYI!tr.dldr
BitDefenderThetaGen:NN.ZemsilF.34806.pm0@auBf!om
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A

How to remove MSIL/TrojanDownloader.Agent.JYI?

MSIL/TrojanDownloader.Agent.JYI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment