Trojan

What is “MSIL/TrojanDownloader.Agent.LZI”?

Malware Removal

The MSIL/TrojanDownloader.Agent.LZI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.LZI virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.LZI?


File Info:

name: CD076E623600B3F078FC.mlw
path: /opt/CAPEv2/storage/binaries/de777ad29c89fb20b06167f479bee33c94acd2c754c3551deef1d5ece5659527
crc32: ECE1D434
md5: cd076e623600b3f078fc5736bfb09e72
sha1: 6a9b4c86f3b6909797c717ea10e5a9aa108fa6d5
sha256: de777ad29c89fb20b06167f479bee33c94acd2c754c3551deef1d5ece5659527
sha512: caf52cf58e109cab9db44260cb1f288c66c68c854492a1b7c5f5ce05cdb30ce5b40abb2bc22e375c67beafaed76eb6c7618873dea774def84399ccaa42a068bf
ssdeep: 6144:i9bMrHB4fuqlaqMfD7w/79khCD1gPjxJcbp8IjxDJwkIwegw6KMLRQIkeFqEDEtm:iSrH22qla5w/yXbxixFcRMFQIkeNCSoG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DD840295FB580E5EE8F94F3F48EB8321BB46A7D0824B9F2B1E91185E59439C32DC059C
sha3_384: 06496301d28367473bae0ea2303c7c26097617c57a7510c0ecf10ab91cbae524cc807a79bee8eaffd8e336ab06c24362
ep_bytes:
timestamp: 2102-05-03 16:05:48

Version Info:

0: [No Data]

MSIL/TrojanDownloader.Agent.LZI also known as:

BkavW32.AIDetectNet.01
AlibabaTrojan:MSIL/Generic.30ca3fb4
Cybereasonmalicious.6f3b69
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.LZI
Paloaltogeneric.ml
TencentMsil.Trojan-downloader.Agent.Syhr
ComodoHeur.Corrupt.PE@1z141z3
ZillyaDownloader.Agent.Win32.472461
McAfee-GW-EditionArtemis
SophosGeneric PUA GK (PUA)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
APEXMalicious
IkarusTrojan.Inject
FortinetMSIL/Agent.LZI!tr.dldr
CrowdStrikewin/malicious_confidence_70% (W)

How to remove MSIL/TrojanDownloader.Agent.LZI?

MSIL/TrojanDownloader.Agent.LZI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment