Trojan

What is “MSIL/TrojanDropper.Agent.DMB”?

Malware Removal

The MSIL/TrojanDropper.Agent.DMB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.DMB virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine MSIL/TrojanDropper.Agent.DMB?


File Info:

crc32: 69BEAB60
md5: 8b87f3f25e42c1dd73a89d16fa199fc7
name: 8B87F3F25E42C1DD73A89D16FA199FC7.mlw
sha1: 710e31cf8e6c22b6f045974094983c0f0127ecd1
sha256: 3813562b7b96f88a1d8376c34008b9d8389966f43b7dc5d2034ce1bce736396f
sha512: 2cdf81cf1afe764f37574d7dadf9a86b3f1a42a87585b9a92015603426cfc6ed890cec2c00c6fb3c3fb9b8046e7f36e76e0df8435a4c3dca34ccb55e1252375d
ssdeep: 24576:W/Bqtd1o2fJnKmP0IGyd7/bcaZ1MFWNEpA/d59/D0jwJhWt9ye/e:WO1omis7TcaZ1MF6Eu/d59rnJhiye/e
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: Program.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Program
ProductVersion: 1.0.0.0
FileDescription: Program
OriginalFilename: Program.exe

MSIL/TrojanDropper.Agent.DMB also known as:

K7AntiVirusTrojan ( 005243cb1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.BitPyLock.1
CylanceUnsafe
SangforRansom.Win32.BitPyLock.1
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 005243cb1 )
Cybereasonmalicious.25e42c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DMB
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.BitPyLock.1
NANO-AntivirusTrojan.Win32.Crypt.eryyvl
MicroWorld-eScanGen:Variant.Ransom.BitPyLock.1
TencentWin32.Trojan.Generic.Ecuh
Ad-AwareGen:Variant.Ransom.BitPyLock.1
SophosMal/Generic-S
ComodoMalware@#3qowolr8lmy14
BitDefenderThetaGen:NN.ZexaF.34058.fnKfayiIcAf
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.8b87f3f25e42c1dd
EmsisoftGen:Variant.Ransom.BitPyLock.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Refroso.k
AviraHEUR/AGEN.1139340
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Glupteba!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.BitPyLock.1
McAfeeArtemis!8B87F3F25E42
MAXmalware (ai score=84)
PandaTrj/CI.A
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Agent.DMB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASXgA

How to remove MSIL/TrojanDropper.Agent.DMB?

MSIL/TrojanDropper.Agent.DMB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment