Trojan

MSIL/TrojanDownloader.Agent_AGen.IT (file analysis)

Malware Removal

The MSIL/TrojanDownloader.Agent_AGen.IT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent_AGen.IT virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent_AGen.IT?


File Info:

name: 0466C9886A6CB0B6C8B8.mlw
path: /opt/CAPEv2/storage/binaries/72c58ff6e0c44702c35229ac7cb272e6e2ca9ce88c47831618bead6d4d2e2b7e
crc32: 9A666B47
md5: 0466c9886a6cb0b6c8b846e57850e352
sha1: cb7a953712554834a6b69ade14e6840c58e5e9e8
sha256: 72c58ff6e0c44702c35229ac7cb272e6e2ca9ce88c47831618bead6d4d2e2b7e
sha512: 8b77d4d12339c86face84c865f9af1e1f2eed363a79573212c619e04021009efe453a9b2dbbe533e699336b4e5f57561cf772975752a396636251cfd789b70d1
ssdeep: 384:BGVDAV1iOHUUXBCIhX3ADQ/gPMOatusHYKuh6umX2I8VxhYO7meY:BGlTGIIhX3AD2+lqYfmEVJo
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T145B21791B65CCA74F5654B3ECC63DC9803B9EE019B23C11BB086332FE936B49EA15360
sha3_384: f8e1d13633925d8ca5a5cb9c16f29f33d98e46988fc82850e69217c1068a34de1e7f48661276a9fe98fea376a5103883
ep_bytes: ff250020400000000000000000000000
timestamp: 2105-08-05 21:11:27

Version Info:

Translation: 0x0000 0x04b0
Comments: NVIDIA GeForce NOW
CompanyName: NVIDIA Corporation
FileDescription: NVIDIA GeForce NOW
FileVersion: 92.4515.159.1
InternalName: Hwhtvy.exe
LegalCopyright: (c) 2017-2021 NVIDIA Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: Hwhtvy.exe
ProductName: NVIDIA GeForce NOW
ProductVersion: 92.4515.159.1
Assembly Version: 92.4515.159.1

MSIL/TrojanDownloader.Agent_AGen.IT also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38903715
FireEyeTrojan.GenericKD.38903715
ALYacTrojan.GenericKD.38903715
CylanceUnsafe
SangforTrojan.Win32.Tiggre.rfn
K7AntiVirusTrojan-Downloader ( 0058e0f01 )
K7GWTrojan-Downloader ( 0058e0f01 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecMSIL.Downloader!gen7
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent_AGen.IT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderTrojan.GenericKD.38903715
AvastWin32:CrypterX-gen [Trj]
Ad-AwareTrojan.GenericKD.38903715
SophosMal/Generic-S
DrWebTrojan.DownloaderNET.283
TrendMicroTROJ_GEN.R002C0PB922
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftTrojan.GenericKD.38903715 (B)
IkarusTrojan-Downloader.MSIL.Agent
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1232073
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Tiggre!rfn
GDataTrojan.GenericKD.38903715
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4956885
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MCrypt.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0PB922
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:oSfgGVkZp8z5gF5jGe/bQQ)
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Agent.JFV!tr.dldr
BitDefenderThetaGen:NN.ZemsilCO.34212.bm0@aaUiHlm
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A

How to remove MSIL/TrojanDownloader.Agent_AGen.IT?

MSIL/TrojanDownloader.Agent_AGen.IT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment