Trojan

MSIL/TrojanDropper.Agent.CNM removal instruction

Malware Removal

The MSIL/TrojanDropper.Agent.CNM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.CNM virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Terminates another process
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup

How to determine MSIL/TrojanDropper.Agent.CNM?


File Info:

name: A87D52B45C106313A189.mlw
path: /opt/CAPEv2/storage/binaries/048b8d704ec27bfa606cb29f2610af6a84ad4d714289fb1628c279bfcdefee07
crc32: 38FBE9EE
md5: a87d52b45c106313a18968e4fc781419
sha1: 2c9ac57bba51a32247681def944600da9e45acc7
sha256: 048b8d704ec27bfa606cb29f2610af6a84ad4d714289fb1628c279bfcdefee07
sha512: 2af147ab2dd0aee3ca96cb7922634f9970ffbca5c78fa5e3271d7171e4bf591f70899a819835c624242cd89d4f96ff46d793c5582a518c44acc3371161400b56
ssdeep: 6144:U2sssssssss3sssssssusr9qsssssLsssshsehUssssssssssssssssssssssssO:5ibqI59Pk2cb7puAruXqfez604
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1074549157BA8C692E0A84BB4CD2175F086F0AD35D929DB1F5C403CEE38BA79198537B3
sha3_384: 57d4fd8e5b8cec0dfedc99251b810e8951837f464d43c6e748235a3b13f6782e4ed97b9df064e513463c30c707010d47
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-09-02 17:05:21

Version Info:

Comments: HQ Proxie Scrapper v1.6
CompanyName: Samad.Dz
FileDescription: HQ Proxie Scrapper v1.6
FileVersion: 1.2.0.0
InternalName: HQ Proxie Scrapper v1.6.exe
LegalCopyright: Copyright © Samad.Dz 2019
OriginalFilename: HQ Proxie Scrapper v1.6.exe
ProductName: HQ Proxie Scrapper v1.6
ProductVersion: 1.2.0.0
Assembly Version: 1.2.0.0
Translation: 0x0000 0x04b0

MSIL/TrojanDropper.Agent.CNM also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Fsysna.4!c
MicroWorld-eScanGen:Variant.Ser.MSILHeracles.270
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacTrojan.MSIL.Agent
CylanceUnsafe
VIPREGen:Variant.Ser.MSILHeracles.270
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004f72fd1 )
AlibabaTrojan:MSIL/Fsysna.409a0810
K7GWTrojan ( 004f72fd1 )
Cybereasonmalicious.45c106
CyrenW32/MSIL_Perseus.AB.gen!Eldorado
SymantecTrojan.Dropper!g4
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.CNM
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.MSIL.Fsysna.gen
BitDefenderGen:Variant.Ser.MSILHeracles.270
NANO-AntivirusTrojan.Win32.Fsysna.gbnpkq
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan.Fsysna.Lnej
Ad-AwareGen:Variant.Ser.MSILHeracles.270
EmsisoftGen:Variant.Ser.MSILHeracles.270 (B)
ComodoMalware@#194krjfs3f8dz
DrWebTrojan.MulDrop10.30050
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Ser.MSILHeracles.270
IkarusTrojan-Dropper.MSIL.Agent
GDataGen:Variant.Ser.MSILHeracles.270
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASSuf.2B514
ArcabitTrojan.Ser.MSILHeracles.270
MicrosoftTrojan:MSIL/Bladabindi
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C3471112
Acronissuspicious
McAfeeArtemis!A87D52B45C10
MalwarebytesMalware.AI.4228054050
RisingDropper.Agent!8.2F (C64:YzY0Om5gBOpyIgbq)
YandexTrojan.Fsysna!lpxEcBkmR5M
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73694066.susgen
FortinetMSIL/Agent.CNM!tr.dldr
BitDefenderThetaGen:NN.ZemsilF.34806.ir0@aGY!Lnf
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDropper.Agent.CNM?

MSIL/TrojanDropper.Agent.CNM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment