Trojan

MSIL/TrojanDownloader.Agent.KGX removal instruction

Malware Removal

The MSIL/TrojanDownloader.Agent.KGX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.KGX virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.KGX?


File Info:

name: A50B723CA34D667BC8A6.mlw
path: /opt/CAPEv2/storage/binaries/0e3a1afc75082774e0c931bfedb80348c9042ac0e88071a0918207c6a1b358d4
crc32: 7A97E754
md5: a50b723ca34d667bc8a646a34c61f65f
sha1: 36c89b3461d65e86636060a1dd8e2fdbaefb5bc7
sha256: 0e3a1afc75082774e0c931bfedb80348c9042ac0e88071a0918207c6a1b358d4
sha512: dbe67ca37a8da65756375c1985f01d0b02ba7c86a4e3d5e3ca48c4f5056d7e507fcf8e751a60d2bde489815f632b1d2732ff8422d0ef240f2297c426a80e42d7
ssdeep: 3072:SrwBbI480rYtB0I1sd62QKUTNpq27R7qEBgqdBcm+8cUYua2O3c9KQGhYsuE1q:msbgmdGKUTNpsqdG5h5AO3N/hYsuE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF346CC2F8004590EC3E4A31A0694D5643523D7AECB4A35D6B8DB69A3BF32E7553788F
sha3_384: 645c1b679e0809dc5e69d7b3ae32fea984bf0dd6040fe571a1e0e2337c17c160f953ceb05ebdd37c68a83fdb9e295f31
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-01 15:40:37

Version Info:

Translation: 0x0000 0x04b0
Comments: Firefox
CompanyName: Mozilla
FileDescription: Firefox
FileVersion: 18.5.0.0
InternalName: Abmbbtg.exe
LegalCopyright: Mozilla
LegalTrademarks:
OriginalFilename: Abmbbtg.exe
ProductName: Firefox
ProductVersion: 18.5.0.0
Assembly Version: 18.5.0.0

MSIL/TrojanDownloader.Agent.KGX also known as:

LionicTrojan.MSIL.Agensla.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48218847
FireEyeGeneric.mg.a50b723ca34d667b
McAfeeRDN/Generic PWS.y
CylanceUnsafe
SangforInfostealer.MSIL.Agensla.gen
K7AntiVirusTrojan-Downloader ( 0058dd6a1 )
AlibabaTrojanPSW:MSIL/Agensla.acd39636
K7GWTrojan-Downloader ( 0058dd6a1 )
BitDefenderThetaGen:NN.ZemsilF.34212.pm0@aaOLtEo
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.KGX
TrendMicro-HouseCallTROJ_GEN.R06CC0PB522
Paloaltogeneric.ml
ClamAVWin.Malware.Cyzd-6937835-0
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.48218847
AvastWin32:DropperX-gen [Drp]
Ad-AwareTrojan.GenericKD.48218847
SophosMal/Generic-S
ZillyaDownloader.Agent.Win32.461139
TrendMicroTROJ_GEN.R06CC0PB522
McAfee-GW-EditionRDN/Generic PWS.y
EmsisoftTrojan.GenericKD.48218847 (B)
IkarusTrojan-Downloader.MSIL.Agent
GDataTrojan.GenericKD.48218847
Antiy-AVLTrojan/Generic.ASMalwS.35201B9
ArcabitTrojan.Generic.D2DFC2DF
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.48218847
MAXmalware (ai score=84)
MalwarebytesTrojan.MCrypt.MSIL.Generic
APEXMalicious
RisingMalware.Obfus/MSIL@AI.95 (RDM.MSIL:ITMbOWkFrYYYdPHe6HAXKQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/TrojanDownloader.Agent.KGX?

MSIL/TrojanDownloader.Agent.KGX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment