Trojan

MSIL/TrojanDownloader.Agent.KHG malicious file

Malware Removal

The MSIL/TrojanDownloader.Agent.KHG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.KHG virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.KHG?


File Info:

name: D50298F0C5BED6BD2BF8.mlw
path: /opt/CAPEv2/storage/binaries/6e8462d59d69c99653963c59190734c4741cc9e8da428fdec844a7fa1ed7b2d1
crc32: F0F8BFC8
md5: d50298f0c5bed6bd2bf8aad7ba03ff00
sha1: 9222f3db36bd220b665c892066002a628f616449
sha256: 6e8462d59d69c99653963c59190734c4741cc9e8da428fdec844a7fa1ed7b2d1
sha512: dc02f3a70f77900a4c6c95ca7edcd2fcdc22b7a4042456afb4146a848904ed3c0ae6c198f55930af51f51353cf82a6f7c3ad3d871394ac91c7241809b150f856
ssdeep: 768:3ltSEIcC1gJ7+jZUqQG/RtTjlfDpWFeOUpF95zSgK4x0/klGpn7X04A:VtStN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE73DCEE1A90D034C443CA38B4312A0E346FEE976A3E761D7467FE7A5F762162805D0A
sha3_384: d7ba52e3dc0a3b3eac18d1103d8de20c0a0c7ac0bf66c46a7dc50fe28d7c8dcfa5a8cf40d210463d6a48e9f843bfd203
ep_bytes: ff250020400000000000000000000000
timestamp: 2053-09-06 12:00:37

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: LoaderFor@Aureliun_v2
FileVersion: 1.0.0.0
InternalName: LoaderFor@Aureliun_v2.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: LoaderFor@Aureliun_v2.exe
ProductName: LoaderFor@Aureliun_v2
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.KHG also known as:

LionicTrojan.MSIL.PsDownload.a!c
MicroWorld-eScanTrojan.GenericKD.48317151
FireEyeGeneric.mg.d50298f0c5bed6bd
ALYacTrojan.GenericKD.48317151
CylanceUnsafe
SangforTrojan.MSIL.PsDownload.gen
K7AntiVirusTrojan-Downloader ( 0058dff81 )
AlibabaTrojanDownloader:MSIL/PsDownload.9dba2ef1
K7GWTrojan-Downloader ( 0058dff81 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34212.em0@aWEZMXi
CyrenW32/Trojan.JPWZ-4170
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/TrojanDownloader.Agent.KHG
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.48317151
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan-downloader.Agent.Wofi
Ad-AwareTrojan.GenericKD.48317151
ComodoMalware@#1vix82p5is9cu
TrendMicroTROJ_GEN.R002C0PB322
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftTrojan.GenericKD.48317151 (B)
IkarusTrojan-Downloader.MSIL.Tiny
GDataTrojan.GenericKD.48317151
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1240931
Antiy-AVLTrojan/Generic.ASMalwS.351DA4F
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4934425
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Downloader.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0PB322
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:pbfjt3VyN2c25vcK6k+lEA)
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat
AVGWin32:DropperX-gen [Drp]
PandaTrj/CI.A

How to remove MSIL/TrojanDownloader.Agent.KHG?

MSIL/TrojanDownloader.Agent.KHG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment