Trojan

MSIL/TrojanDownloader.Agent.MJO (file analysis)

Malware Removal

The MSIL/TrojanDownloader.Agent.MJO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.MJO virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.MJO?


File Info:

name: 3D2AA96E0C0FC96E532F.mlw
path: /opt/CAPEv2/storage/binaries/74a098344fb282c483eaae1b536e90a6cbd78cbb8a7c4857bac3d65e05e70c75
crc32: E647D1C2
md5: 3d2aa96e0c0fc96e532f8de3aab5b129
sha1: c796b358eef688f21e84a8664356fc6120158d78
sha256: 74a098344fb282c483eaae1b536e90a6cbd78cbb8a7c4857bac3d65e05e70c75
sha512: de2b4f5e16773db49261b05d9f369b054a5ed6e654b2be5aa35c279b10d34ef9d0ab5e0fa0207ee11e8597f61f14b1355f7f3ec2f246b86119a6658fc87785da
ssdeep: 12288:/D1XDTyUGFpTwCDfwR7N1ljwV17dZixJBFqDk1ILuFatDGpYlmVqX9lxAzx:5vtaTweoR7N3M77M5GLH3l9lxE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T113F4126285016FD8FE25233110055A766D08EF72333D95E4A4F67E3E3A30A4B1AB777A
sha3_384: 31e34ff51a8bd48a62d603439475d2fc3221bada3783ce746dd691b769b1d967506e863839b2503de3a9f6a5b7396f35
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-29 08:54:47

Version Info:

Translation: 0x0000 0x04b0
Comments: WinRAR archiver
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 5.80.0.0
InternalName: order 6292022.exe
LegalCopyright: Copyright © Alexander Roshal 1993-2019
LegalTrademarks:
OriginalFilename: order 6292022.exe
ProductName: WinRAR
ProductVersion: 5.80.0.0
Assembly Version: 5.80.0.0

MSIL/TrojanDownloader.Agent.MJO also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
FireEyeGeneric.mg.3d2aa96e0c0fc96e
CylanceUnsafe
Cybereasonmalicious.8eef68
CyrenW32/MSIL_Kryptik.GYT.gen!Eldorado
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.MJO
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AvastWin32:DropperX-gen [Drp]
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.MSIL.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!3D2AA96E0C0F
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:mO+rmWCYPgUAVIEdgdel8g)
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.MIW!tr
BitDefenderThetaGen:NN.ZemsilF.34742.Wm0@a8IkUwl
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove MSIL/TrojanDownloader.Agent.MJO?

MSIL/TrojanDownloader.Agent.MJO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment