Trojan

MSIL/TrojanDropper.Agent.BSR removal instruction

Malware Removal

The MSIL/TrojanDropper.Agent.BSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.BSR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the njRat malware family
  • Exhibits behavior characteristic of CodeLux Keylogger
  • Creates known Njrat/Bladabindi RAT registry keys
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine MSIL/TrojanDropper.Agent.BSR?


File Info:

name: 18D86809F614B69FC739.mlw
path: /opt/CAPEv2/storage/binaries/6dc4d6c711942dc1500f2af348d074d74ee2a2dc3c975b466e71380d9da38eea
crc32: 550C6045
md5: 18d86809f614b69fc739adba1501b0af
sha1: 136f85e62b6f6fa380229e5fda8944950f474490
sha256: 6dc4d6c711942dc1500f2af348d074d74ee2a2dc3c975b466e71380d9da38eea
sha512: 65193ad6e2ebbb62e8437cd6b8f4f96164ee2f8d9621fcd24fd4db9d662797f03c031fd877d79865c4e14b9615eac561a213fddbae7460dc857d2adf935b4106
ssdeep: 12288:fkskzoHFMugPLtjosKGN6JVXIqJL6mp9GHGbjml7:fksmbI1jGJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6F4BC2429EF501EB373EEAC4BC4B9BE996EFAB3270A24B9207117464323D41DD91735
sha3_384: 3b3ceccfa42afe526b83547b43c00224558f622532309e6a322211eadc04020a1395a4f7e1b45fd204857bd09101e9b8
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-10-18 17:03:21

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Keygen.exe
LegalCopyright:
OriginalFilename: Keygen.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/TrojanDropper.Agent.BSR also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Krypt.41
McAfeeArtemis!18D86809F614
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3de1 )
AlibabaTrojan:MSIL/Tiggre.bfb71dbb
K7GWTrojan ( 0055e3de1 )
Cybereasonmalicious.9f614b
CyrenW32/MSIL_Kryptik.COX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.BSR
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1359329
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.MSIL.Krypt.41
NANO-AntivirusTrojan.Win32.Bladabindi.ehqujh
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Eaxs
Ad-AwareGen:Heur.MSIL.Krypt.41
SophosML/PE-A + Mal/MsilDrop-B
ComodoTrojWare.MSIL.Agent.GH@60rvah
DrWebBackDoor.Bladabindi.1056
ZillyaDropper.Agent.Win32.225840
McAfee-GW-EditionBehavesLike.Win32.Generic.bt
FireEyeGeneric.mg.18d86809f614b69f
EmsisoftGen:Heur.MSIL.Krypt.41 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.MSIL.Krypt.41
JiangminTrojan.Generic.gdyd
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.15C0C4C
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win32.KeyGen.C1872274
BitDefenderThetaAI:Packer.1493E6BB1F
ALYacGen:Heur.MSIL.Krypt.41
MAXmalware (ai score=86)
MalwarebytesCrackTool.Agent.Keygen
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL:3zPCHXtv9ciglp0UyxJSiw)
YandexTrojan.Agent!2GcHvMPKMhg
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BSR!tr
WebrootW32.Malware.Gen
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDropper.Agent.BSR?

MSIL/TrojanDropper.Agent.BSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment