Trojan

Should I remove “MSIL/TrojanDropper.Agent.DTL”?

Malware Removal

The MSIL/TrojanDropper.Agent.DTL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.DTL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary

How to determine MSIL/TrojanDropper.Agent.DTL?


File Info:

crc32: 4B431A4B
md5: 3f7c28287d209906cdb8713c814c3683
name: 3F7C28287D209906CDB8713C814C3683.mlw
sha1: 1fe97a19f2039349d1655cd5cf5b5bb2a8349aa1
sha256: f28f500ba73dbc34c9f0fccd180fb8242cbed76891c7b9bb4973f1f5647d904d
sha512: 2f26eef934b9bfcad390ed276e641ae7a1050a2e0c13a86f9021193b149f226243b0861e372ad8f5c30777b3d377e49658552fa58de3b82db37a4b3d6cbe5c94
ssdeep: 98304:Wbfw4BZiZoGsjqcySD1PfaUPSnCx8Gtnfe:Ufw4BZiIjqcDnJSLGd
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: shshshshsh xa9hgshshshs
Assembly Version: 10.13.21.47
InternalName: fin.exe
FileVersion: 10.13.21.47
CompanyName: ghsdhsdh
ProductName: fhsfdhsh
ProductVersion: 10.13.21.47
FileDescription: fdghdfhfdhfdh
OriginalFilename: fin.exe

MSIL/TrojanDropper.Agent.DTL also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.9f2039
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DTL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Miner.gen
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34294.qp0@aO!XMYc
FireEyeGeneric.mg.3f7c28287d209906
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
MalwarebytesRansom.NoCry
IkarusTrojan.Win32.Inject
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/TrojanDropper.Agent.DTL?

MSIL/TrojanDropper.Agent.DTL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment