Trojan

MSIL/TrojanDownloader.Agent.MZW removal tips

Malware Removal

The MSIL/TrojanDownloader.Agent.MZW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.MZW virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.MZW?


File Info:

name: B57ACAF610174A3841D8.mlw
path: /opt/CAPEv2/storage/binaries/60099b51e1c849ccbdc7b111b8c250e307f2459e48c6d1686f56a5e5f7f23469
crc32: 7AFF09A2
md5: b57acaf610174a3841d8d397fc883ef6
sha1: ea0855851da0828d6fa72ffd8a0fbe92ca62d1e5
sha256: 60099b51e1c849ccbdc7b111b8c250e307f2459e48c6d1686f56a5e5f7f23469
sha512: 2dfe5b629f5d0fd4d7a9a131266eafbecedf51a41f66c931ae04a42243e369cd3cc0e6198fe2bdd035954b9067914fd510c46cd16602f501f759cc87f5fc7eda
ssdeep: 3072:LZHxZ1s1Z4YCZQ8JUVov1cTbtCpnQUQTHPwp5:LZHxZ1QEZQ86Vov3D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17BF3FC2C37AC4372C5EE4F7419ABF002B1BC6CA39D759BBD05C945BFC901A4A650D2BA
sha3_384: 149835f5ec8f929a51a0e4163ebbce84e7f8947eac10538ef630f14679a14e510faf41e65c5f9651e38ec1cabc296d4e
ep_bytes: ff2544a94200000000000000000018a9
timestamp: 2022-08-17 03:18:34

Version Info:

Translation: 0x0000 0x04b0
Comments: System.Runtime.Caching.Configuration.MemoryCacheSettingsCollection
FileDescription: System.Runtime.Caching.Configuration.MemoryCacheSettingsCollection
FileVersion: 1.0.0.0
InternalName: qRYTi.exe
LegalCopyright: System.Runtime.Caching.Configuration.MemoryCacheSettingsCollection Copyright © 2014
OriginalFilename: qRYTi.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.MZW also known as:

CynetMalicious (score: 99)
FireEyeTrojan.GenericKDZ.91069
McAfeeArtemis!B57ACAF61017
VIPRETrojan.GenericKDZ.91069
SangforSuspicious.Win32.Save.a
CyrenW32/MSIL_Agent.DUA.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.MZW
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderTrojan.GenericKDZ.91069
MicroWorld-eScanTrojan.GenericKDZ.91069
AvastWin32:RATX-gen [Trj]
Ad-AwareTrojan.GenericKDZ.91069
EmsisoftTrojan.GenericKDZ.91069 (B)
McAfee-GW-EditionArtemis
IkarusTrojan-Downloader.MSIL.Agent
GDataTrojan.GenericKDZ.91069
AviraTR/Dldr.Agent.bwqml
Antiy-AVLTrojan/Generic.ASMalwS.6EF0
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5225095
BitDefenderThetaGen:NN.ZemsilF.34606.km0@aWVTyxh
ALYacTrojan.GenericKDZ.91069
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Agent.MQA!tr
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/TrojanDownloader.Agent.MZW?

MSIL/TrojanDownloader.Agent.MZW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment