Trojan

MSIL/TrojanDownloader.Agent.NMO malicious file

Malware Removal

The MSIL/TrojanDownloader.Agent.NMO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.NMO virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/TrojanDownloader.Agent.NMO?


File Info:

name: DF2745E8AE4AD1A3AA3C.mlw
path: /opt/CAPEv2/storage/binaries/3bcf1f4732835c14c9615109c1275a520d96d768da30d4a0005e8e68f7fb7f56
crc32: AF81463D
md5: df2745e8ae4ad1a3aa3c4d6eed35d937
sha1: a2edc822097b2b5fa1c42aeeddd81483b1722151
sha256: 3bcf1f4732835c14c9615109c1275a520d96d768da30d4a0005e8e68f7fb7f56
sha512: 1e3aa1b861ada8373d7298f2588e62dbf370f4e8aedccad188ff6ea654cc909fd08e6b7aa724a0a6c98e23ecff7e1a7547996943cbafcfb83f83953f4cf9205c
ssdeep: 768:cLxl4JLkrxr/rYrPrgr9rnrurZrfrwrmr7ryrArSrxrTrbrvSHFl0GMTusEi2/ls:aSHf0gsEltGbVx4LU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C63A89B3540C89CCE6D24F76306408073E99CFFD958A2486BCE32572FE65E2583676E
sha3_384: ac7027b5202a8629357d7b4e61c9083f6ae464244c920138ee108b6b7c5e85a7371d62df24a5bee0758a815bdb3c8762
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-26 08:16:00

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: JxzwYzvEYdxxf.exe
LegalCopyright:
OriginalFilename: JxzwYzvEYdxxf.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/TrojanDownloader.Agent.NMO also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.62608458
McAfeeRDN/Generic BackDoor
CylanceUnsafe
VIPRETrojan.GenericKD.62608458
SangforDownloader.Msil.Leonem.Vcr6
K7AntiVirusTrojan-Downloader ( 00598b1f1 )
K7GWTrojan-Downloader ( 00598b1f1 )
Cybereasonmalicious.2097b2
CyrenW32/ABRisk.ULKP-6764
SymantecMSIL.Downloader!gen7
ESET-NOD32MSIL/TrojanDownloader.Agent.NMO
APEXMalicious
Paloaltogeneric.ml
AlibabaBackdoor:MSIL/Bladabindi.1bfd5633
Ad-AwareTrojan.GenericKD.62608458
SophosMal/Generic-S
ComodoMalware@#130qo7ey4f6l0
BitDefenderThetaGen:NN.ZemsilF.34754.em0@aK@jUhe
ZillyaDownloader.Agent.Win32.491586
TrendMicroTROJ_GEN.R002C0DIT22
McAfee-GW-EditionBehavesLike.Win32.AdwareTskLnk.lm
EmsisoftTrojan.GenericKD.62608458 (B)
AviraHEUR/AGEN.1240957
Antiy-AVLTrojan/Generic.ASMalwS.3DAC
KingsoftWin32.Hack.Undef.(kcloud)
ArcabitTrojan.Generic.D3BB544A
GoogleDetected
AhnLab-V3Trojan/Win.Leonem.C5246209
Acronissuspicious
MAXmalware (ai score=82)
MalwarebytesTrojan.Downloader.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0DIT22
TencentMsil.Trojan-Downloader.Ader.Ogil
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.BEU!tr.dldr
PandaTrj/GdSda.A

How to remove MSIL/TrojanDownloader.Agent.NMO?

MSIL/TrojanDownloader.Agent.NMO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment