Trojan

What is “MSIL/TrojanDropper.Agent.ESS”?

Malware Removal

The MSIL/TrojanDropper.Agent.ESS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.ESS virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine MSIL/TrojanDropper.Agent.ESS?


File Info:

crc32: D6DBE101
md5: c7a17bcf8c91a6f72903416a67676478
name: upload_file
sha1: 001a856127e36a3f6675a3620d1c8ceefe436381
sha256: fbdd9d0e1691146adbaf3e8c51410b6cfe85472d2451ae74c98b7691ce943234
sha512: c2423b3f9719a147673627a031db4553d12a8c73ee740904423201bc0362d46423aa48af4cbbd8b8e374f9bb910fdd769a8218a961df0aab16f12ae5d7a702c3
ssdeep: 12288:Dhzj0s5KKJDHZ6Bm6Pfx1Bpn5lzut25lKNFllUWPEeNP5cW68q4F879DSNfz+Nc:FwKFkBTP7Lzcf/P1Fh68q4q792L+VOL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/TrojanDropper.Agent.ESS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.54078
FireEyeGeneric.mg.c7a17bcf8c91a6f7
CAT-QuickHealTrojanDropper.MSIL
Qihoo-360Generic/Trojan.Dropper.e44
McAfeeRDN/Generic Dropper
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Dapato.b!c
SangforMalware
K7AntiVirusTrojan ( 00565d381 )
BitDefenderGen:Variant.Barys.54078
K7GWTrojan ( 00565d381 )
Cybereasonmalicious.f8c91a
TrendMicroTROJ_GEN.R002C0PJH20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Dropper.MSIL.Dapato.gen
AlibabaTrojanDropper:MSIL/Dapato.e268ab16
ViRobotTrojan.Win32.Z.Barys.741888
TencentMsil.Trojan-dropper.Dapato.Szuv
Ad-AwareGen:Variant.Barys.54078
EmsisoftGen:Variant.Barys.54078 (B)
ComodoMalware@#hfnzxqbfr9cd
F-SecureHeuristic.HEUR/AGEN.1105300
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
AviraHEUR/AGEN.1105300
Antiy-AVLTrojan[Dropper]/MSIL.Agent
MicrosoftTrojan:Win32/Ymacco.AAFB
ZoneAlarmHEUR:Trojan-Dropper.MSIL.Dapato.gen
GDataGen:Variant.Barys.54078
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34590.TmW@aa0KH3h
ALYacGen:Variant.Barys.54078
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.ESS
TrendMicro-HouseCallTROJ_GEN.R002C0PJH20
YandexTrojan.DR.Agent!rvtOxn4VE68
IkarusTrojan-Dropper.MSIL.Agent
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Agent.ESS!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDropper.Agent.ESS?

MSIL/TrojanDropper.Agent.ESS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment