Trojan

MSIL/TrojanDropper.Agent.AYE malicious file

Malware Removal

The MSIL/TrojanDropper.Agent.AYE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.AYE virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Created a process from a suspicious location

How to determine MSIL/TrojanDropper.Agent.AYE?


File Info:

name: 8FF978049AC9C4EF23E7.mlw
path: /opt/CAPEv2/storage/binaries/b059824d0ee39a09dea61d74adc6b412434a9c1fd628141ee4643d98da65a741
crc32: 8E33CBC2
md5: 8ff978049ac9c4ef23e757ddc6931a68
sha1: 421299e24861c20a06b3439437f063f375714aa7
sha256: b059824d0ee39a09dea61d74adc6b412434a9c1fd628141ee4643d98da65a741
sha512: 331a74ea2916e32553e7c7fd9ed181bcb489e3ef029e5cbb77e88dc1e3ba3c511aab9041edd54e7bef56ac85dae730793ef477afbd928e2d54b4c279e82d5c2a
ssdeep: 384:2zRqSb07LLTVZIb5XVrrEcxIgJtFXVrtEcxIpXAYRkq/BRdXVrrEcxIlJC48k/p/:4hb2RaGyGlAYRtGlJC488aY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F7C27C1646A74671C6C94A3DC8AFF26336BCF923D0F7966977A41D134E002A3C573A2A
sha3_384: 20a8bde4be5eb556c989322dca1270de93efabf5849294fdbf839170f2b5c2a4ba5c1b773fdaff2939749fe93f699a2a
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-05-04 14:56:47

Version Info:

FileDescription:
FileVersion: 1.0.0.0
InternalName: DupperClient.exe
LegalCopyright: Copyright © 2020
OriginalFilename: DupperClient.exe
ProductName: DupperClient
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0
Translation: 0x0000 0x04b0

MSIL/TrojanDropper.Agent.AYE also known as:

LionicTrojan.Win32.Generic.lm6x
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen.28857
FireEyeGeneric.mg.8ff978049ac9c4ef
CylanceUnsafe
ZillyaDropper.Agent.Win32.462763
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 004b1ef01 )
AlibabaTrojan:MSIL/DNetDrp.02848b3e
K7GWTrojan ( 004b1ef01 )
Cybereasonmalicious.49ac9c
BitDefenderThetaGen:NN.ZemsilF.34294.bm0@a0IpV@l
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.AYE
TrendMicro-HouseCallTROJ_GEN.R002C0PIG21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Comet.cwybmo
AvastWin32:DropperX-gen [Drp]
SophosMal/Generic-R + Troj/DNetDrp-AM
ComodoWorm.MSIL.Generic.A@495g2n
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PIG21
McAfee-GW-EditionPWS-Zbot.gen.gt
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.exymg
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.306B172
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 99)
McAfeePWS-Zbot.gen.gt
VBA32TScope.Trojan.MSIL
APEXMalicious
TencentWin32.Trojan.Generic.Egyr
YandexTrojan.DR.Agent!HSvZxkHOJ4c
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Dropper.PKC!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDropper.Agent.AYE?

MSIL/TrojanDropper.Agent.AYE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment