Trojan

MSIL/TrojanDropper.Agent.CHC removal instruction

Malware Removal

The MSIL/TrojanDropper.Agent.CHC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.CHC virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine MSIL/TrojanDropper.Agent.CHC?


File Info:

name: 30A744B0FB9FE503A5E2.mlw
path: /opt/CAPEv2/storage/binaries/5ef5f0eab4b06b2ba6e28175536f04f98f2dcd0bf67a0b9e21903985e2828dd4
crc32: 846C32DD
md5: 30a744b0fb9fe503a5e21e1705b3b44e
sha1: 0a8d8e4ee20e6cc38e713d740799995bb67d5ba5
sha256: 5ef5f0eab4b06b2ba6e28175536f04f98f2dcd0bf67a0b9e21903985e2828dd4
sha512: fb7ba9d72ff2bde2742e4a24156be165f59591cf39c576393aa2876c4ce5898c878036b6d60ff2625d942570216aec605301157f784d7f39d88a8a51c62b9394
ssdeep: 768:mjAI8xgo0WYTf3iTr08w2e0dguJcF4Qhc4VjsS8jdYKNu6LUEXcgA0:I8SbWYL3iH08w2r2hBjsVw18z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19273662629FB109DF3A79EB21FC9F8FF886AE977551D30B631411B068722E408D52736
sha3_384: 9858d6ac4cfb06720a7a22abbd5f453ed154a0e06978d3a77fefb24f21b66b7d12003d1dcbead4f6d7dc930303be7a61
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-03-11 11:54:52

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: WindowsApplication1
FileVersion: 1.0.0.0
InternalName: WindowsApplication1.exe
LegalCopyright: Copyright © Microsoft 2016
OriginalFilename: WindowsApplication1.exe
ProductName: WindowsApplication1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/TrojanDropper.Agent.CHC also known as:

BkavW32.AIDetectNet.01
LionicHeuristic.File.Generic.00×1!p
DrWebBackDoor.Bladabindi.13334
MicroWorld-eScanGen:Trojan.Heur.DNP.eq0@ayKyRjf
FireEyeGeneric.mg.30a744b0fb9fe503
CAT-QuickHealBackdoor.Fynloski.A3
ALYacGen:Trojan.Heur.DNP.eq0@ayKyRjf
CylanceUnsafe
VIPREGen:Trojan.Heur.DNP.eq0@ayKyRjf
SangforBackdoor.Win32.Bladabindi.8
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Bladabindi.4ea3f88c
K7GWTrojan ( 0055e3de1 )
K7AntiVirusTrojan ( 0055e3de1 )
BitDefenderThetaAI:Packer.0DBC8CF21F
VirITBackdoor.Win32.Bladabindi.TSW
CyrenW32/MSIL_Kryptik.CWS.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.CHC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Ursu-8015308-0
KasperskyHEUR:Backdoor.MSIL.Generic
BitDefenderGen:Trojan.Heur.DNP.eq0@ayKyRjf
NANO-AntivirusTrojan.Win32.Bladabindi.eaybhr
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114c0426
Ad-AwareGen:Trojan.Heur.DNP.eq0@ayKyRjf
SophosML/PE-A
ComodoTrojWare.MSIL.Agent.GH@60rvah
ZillyaDropper.Agent.Win32.240225
TrendMicroTROJ_GEN.R067C0DHJ22
McAfee-GW-EditionBackDoor-NJRat.a
EmsisoftGen:Trojan.Heur.DNP.eq0@ayKyRjf (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraHEUR/AGEN.1241429
Antiy-AVLTrojan/Generic.ASMalwS.19D4
MicrosoftBackdoor:MSIL/Bladabindi.B
ArcabitTrojan.Heur.DNP.ED4140
GDataGen:Trojan.Heur.DNP.eq0@ayKyRjf
CynetMalicious (score: 99)
Acronissuspicious
McAfeeBackDoor-NJRat.a
MAXmalware (ai score=83)
MalwarebytesMalware.AI.3192193298
RisingTrojan.Generic/MSIL@AI.90 (RDM.MSIL:ivoEFGD4c1SiW2gomTl43Q)
YandexTrojan.Disfa!FJOzrr6qDZU
IkarusTrojan-PSW.ILUSpy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.NXR!tr
AVGWin32:Malware-gen
Cybereasonmalicious.0fb9fe
PandaTrj/GdSda.A

How to remove MSIL/TrojanDropper.Agent.CHC?

MSIL/TrojanDropper.Agent.CHC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment