Trojan

How to remove “MSIL/TrojanDownloader.Agent.MEP”?

Malware Removal

The MSIL/TrojanDownloader.Agent.MEP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.MEP virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.MEP?


File Info:

name: 5DDAD05F67924A38BA86.mlw
path: /opt/CAPEv2/storage/binaries/c81044d35d26141f0c67845d97fdd2d764ddcba5cc1f0cd737f936e89f1ba9ee
crc32: B0EBDC11
md5: 5ddad05f67924a38ba86d1cf801fbb8f
sha1: a8183bd5066496072b634d0d47029b59b8f8ca96
sha256: c81044d35d26141f0c67845d97fdd2d764ddcba5cc1f0cd737f936e89f1ba9ee
sha512: 5c88be288f5ab5ee9891ff4d8cb94790c678001d9364a083592fd147a0000393b5b51337f1e188dab54a4ad87da32f91f6c5d0a8f6a013c95a3031a7a9cb76cb
ssdeep: 768:X3GCMIfCNHOIBe+IG3PKn928ghpIxpRr070WmUlKJPv56H0L5LYSJu0A:2NH9Bx63r077NlKJX56HY5L9Ju0A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A813C001377886BBDEBD4FB21C6320E50BB62689B551CBEF2D89464F88E17150651FD3
sha3_384: 937631a7c1db8ea9b65d6a3adb94dbad50415413202dc49da02c92bf7ae99195e50c8da4d36a98c082b73d3648ba20a7
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-08-17 02:05:54

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: WindowsFormsApplication1
FileVersion: 1.0.0.0
InternalName: 111111111111.exe
LegalCopyright: Copyright © Microsoft 2023
OriginalFilename: 111111111111.exe
ProductName: WindowsFormsApplication1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.MEP also known as:

CynetMalicious (score: 100)
FireEyeTrojan.GenericKD.68919846
McAfeeArtemis!5DDAD05F6792
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005946b11 )
AlibabaTrojan:MSIL/Agentb.2172a7a7
K7GWTrojan-Downloader ( 005946b11 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.MEP
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Agentb.gen
BitDefenderTrojan.GenericKD.68919846
MicroWorld-eScanTrojan.GenericKD.68919846
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan-Downloader.Ader.Czlw
EmsisoftTrojan.GenericKD.68919846 (B)
F-SecureHeuristic.HEUR/AGEN.1351270
VIPREGen:Variant.Lazy.381336
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
GDataTrojan.GenericKD.68919846
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1351270
ZoneAlarmHEUR:Trojan.MSIL.Agentb.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZemsilF.36350.cm0@aSBzO4p
ALYacGen:Variant.Lazy.381336
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CHO23
RisingDownloader.Agent!8.B23 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Agent.MEP!tr.dldr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDownloader.Agent.MEP?

MSIL/TrojanDownloader.Agent.MEP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment