Trojan

About “MSIL/TrojanDownloader.Agent_AGen.AHH” infection

Malware Removal

The MSIL/TrojanDownloader.Agent_AGen.AHH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent_AGen.AHH virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent_AGen.AHH?


File Info:

name: B2D225D999129379E63D.mlw
path: /opt/CAPEv2/storage/binaries/fc5dcbbef3e35f2dc89ff33a65d1a25eab588fc67dd32d80ec24edd1fd2b1343
crc32: 0242B53B
md5: b2d225d999129379e63db1a8615cbea9
sha1: d346eec332618c5f624f8ec8e15a05b76317d8e0
sha256: fc5dcbbef3e35f2dc89ff33a65d1a25eab588fc67dd32d80ec24edd1fd2b1343
sha512: 67f36ff098e797385610da8db145d5ffcfcfd56856a52e32ba5f9b62fbdf3ccf11996cadf4f9b72a87b4243915c700d5fc669e8b3bc46ecd382580eb50091345
ssdeep: 24576:PrD8JWv7EmawrC6RGDdv1GHq0/Uogux+XEeb8pJvA8:PvGAE9wrCZdNmCoguWQpO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E352390E50144DBF32F8B36A82B419DF750BE1D08B9427433DE79EA6F73264982C5B5
sha3_384: 4866222ad6ef1d32d53cc1027cefc7677851d46747235384dbc20ba15eb52619fde488478dc061f566b2dde29af82449
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-11-02 05:14:21

Version Info:

Translation: 0x0000 0x04b0
Comments: Telegram Desktop
CompanyName: Telegram FZ-LLC
FileDescription: Telegram Desktop
FileVersion: 4.1.0.0
InternalName: WEDDD.exe
LegalCopyright: Copyright (C) 2014-2022
LegalTrademarks:
OriginalFilename: WEDDD.exe
ProductName: Telegram Desktop
ProductVersion: 4.1.0.0
Assembly Version: 4.1.0.0

MSIL/TrojanDownloader.Agent_AGen.AHH also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
FireEyeGeneric.mg.b2d225d999129379
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CyrenW32/MSIL_Agent.BCR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent_AGen.AHH
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Spy.MSIL.Noon.gen
AvastPWSX-gen [Trj]
SophosGeneric ML PUA (PUA)
AviraTR/Dropper.MSIL.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
BitDefenderThetaGen:NN.ZemsilF.34754.en0@aqGBb4c
MalwarebytesTrojan.MalPack
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.LYC!tr
AVGPWSX-gen [Trj]

How to remove MSIL/TrojanDownloader.Agent_AGen.AHH?

MSIL/TrojanDownloader.Agent_AGen.AHH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment