Trojan

MSIL/TrojanDownloader.Agent_AGen.AIA (file analysis)

Malware Removal

The MSIL/TrojanDownloader.Agent_AGen.AIA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent_AGen.AIA virus can do?

  • Authenticode signature is invalid

How to determine MSIL/TrojanDownloader.Agent_AGen.AIA?


File Info:

name: 21849C3A0D99D2C7A03A.mlw
path: /opt/CAPEv2/storage/binaries/a2a0c9f092551810537148ac26b93f8ce89eb6ca40a47c29f1202ecafc272dc3
crc32: 05921501
md5: 21849c3a0d99d2c7a03ab12b8f580782
sha1: 33e53351c6e99db772ac47a52974270b8d673bbd
sha256: a2a0c9f092551810537148ac26b93f8ce89eb6ca40a47c29f1202ecafc272dc3
sha512: 9deacf0c925d92c63d4a378dc311ca03b065e22020da6d67cbe1c45b7df2dd19143bc84795947ba263758ba5aa60a5440d5f8d30dc6baddcd60bc0a7f726eebd
ssdeep: 3072:/iefIQxz70hzwhwBZnRXajKgl9emG9JU09L9t:/i/uMyhwXReKgl/G9l
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16FC36CB417E88B2CD57D0AB1B070112842F7A31E6930DB2A4E5CB4CE3B6774295E97F6
sha3_384: 510c433f6b413d35f6dc9c54d72cb23fa1e64459f37f7d624da0e923c68d16bd726e39a8b49651eca2a4612472181a6c
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-03-18 21:50:46

Version Info:

Translation: 0x0000 0x04b0
Comments: hmBOtlWTuVmh ZnMBOhWJNfyN EZiTZlcHDRki VYsreVErPKOK
CompanyName: KUtcXwQd OOktdeTkTFEi
FileDescription: JCeJOvNfqvsk CIwrtwNLBZPY mbQNWwvijUgE
FileVersion: 122.1.185.171
InternalName: 92625304a31f_3rd.exe
LegalCopyright: Copyright © 2023
LegalTrademarks: HgpDosRZCGPqiFUOsU
OriginalFilename: 92625304a31f_3rd.exe
ProductName: dFGQOGFRAiYU myjgSZJhbiuiOYobcvxlhH
ProductVersion: 122.1.185.171
Assembly Version: 27.226.217.246

MSIL/TrojanDownloader.Agent_AGen.AIA also known as:

MicroWorld-eScanIL:Trojan.MSILZilla.26386
FireEyeIL:Trojan.MSILZilla.26386
CAT-QuickHealTrojan.Guildma
McAfeeArtemis!21849C3A0D99
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Agent.EIM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent_AGen.AIA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderIL:Trojan.MSILZilla.26386
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.MSIL.Agent.16000581
EmsisoftIL:Trojan.MSILZilla.26386 (B)
F-SecureHeuristic.HEUR/AGEN.1307326
DrWebTrojan.DownLoaderNET.544
VIPREIL:Trojan.MSILZilla.26386
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.moderate.ml.score
SophosTroj/Dwnld-AIM
IkarusTrojan-Downloader.MSIL.Agent
GDataMSIL.Trojan-Downloader.Guildma.D
AviraHEUR/AGEN.1307326
Antiy-AVLGrayWare/MSIL.Zombie.a
ArcabitIL:Trojan.MSILZilla.D6712
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:Win64/Guildma.psyR!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Dacic.C5305567
BitDefenderThetaGen:NN.ZemsilCO.36302.hm0@aOydI7m
ALYacIL:Trojan.MSILZilla.26386
MAXmalware (ai score=85)
VBA32Trojan.MSIL.MalDown.gen
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Heracles.42DE!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove MSIL/TrojanDownloader.Agent_AGen.AIA?

MSIL/TrojanDownloader.Agent_AGen.AIA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment