Trojan

MSIL/TrojanDownloader.Agent.PWG removal

Malware Removal

The MSIL/TrojanDownloader.Agent.PWG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.PWG virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent.PWG?


File Info:

name: 87AD3BF196F35ADC86B8.mlw
path: /opt/CAPEv2/storage/binaries/cba0397e9264404eeac85ddb6023552795f006990fdf4b3016f29ff4d2363cab
crc32: 8BAB9627
md5: 87ad3bf196f35adc86b8e1090ccf9611
sha1: a8c039f835b8e63bb63d20b98bdce9c6bc0ba7d1
sha256: cba0397e9264404eeac85ddb6023552795f006990fdf4b3016f29ff4d2363cab
sha512: 47e957c669b33cdcca9242b82de3888c4af85e0d13ed0f12924bf4127970684a0d5defdcff3e524072d81276392d553d0d6b3de060c0b22d9e2ba7f346a2790b
ssdeep: 384:j7+9Q7fZ7cJtv4L+80KPFoDEWws4Eo5ioZbuU8z5f6ulb2I4f5BlS:9VKhw+99guj+bu/f6uwpfNS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AB21957F9BDAA21C71EC73FE85791400364E242B593FB0EB84F135629C73AAD9102B6
sha3_384: e1b5e2d0937bfaf2cc91f16f4f9c5111a72137403da7aef4e6be00044772137234cf3465919d6f9fe2a8e2f5d376804f
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-11-08 08:14:56

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: Qerpvym.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: Qerpvym.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDownloader.Agent.PWG also known as:

BkavW32.Common.20216531
LionicTrojan.Win32.Seraph.a!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.70285651
FireEyeTrojan.GenericKD.70285651
SkyhighDownloader-FCOY!87AD3BF196F3
ALYacTrojan.GenericKD.70285651
MalwarebytesGeneric.Malware/Suspicious
SangforDownloader.Msil.Seraph.Vu5z
K7AntiVirusTrojan-Downloader ( 005adde01 )
AlibabaTrojanDownloader:MSIL/Seraph.a4b60722
K7GWTrojan-Downloader ( 005adde01 )
BitDefenderThetaGen:NN.ZemsilF.36792.bm0@a0GAwXo
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.PWG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.MSIL.Seraph.gen
BitDefenderTrojan.GenericKD.70285651
RisingDownloader.Agent!8.B23 (CLOUD)
F-SecureHeuristic.HEUR/AGEN.1323344
VIPRETrojan.GenericKD.70285651
TrendMicroTROJ_GEN.R002C0XKF23
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Agent
AviraHEUR/AGEN.1323344
MAXmalware (ai score=85)
Antiy-AVLTrojan[PSW]/MSIL.Stealer
Kingsoftmalware.kb.c.996
ArcabitTrojan.Generic.D4307953
ZoneAlarmHEUR:Trojan-Downloader.MSIL.Seraph.gen
GDataTrojan.GenericKD.70285651
AhnLab-V3Malware/Win.Generic.C5539347
DeepInstinctMALICIOUS
VBA32TScope.Trojan.MSIL
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0XKF23
TencentMalware.Win32.Gencirc.13f4ea3c
YandexTrojan.Igent.b1cFTq.1
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.AJEE!tr
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDownloader.Agent.PWG?

MSIL/TrojanDownloader.Agent.PWG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment