Malware

About “MSIL:Agent-CWF [Trj]” infection

Malware Removal

The MSIL:Agent-CWF [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL:Agent-CWF [Trj] virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL:Agent-CWF [Trj]?


File Info:

name: 5152D559D85E947A08D4.mlw
path: /opt/CAPEv2/storage/binaries/66bd869fa91f2ce6071e7ae3907d3a9672dcaf2e4499291524e225888d756739
crc32: 8C03A275
md5: 5152d559d85e947a08d40423363bf3e6
sha1: 710207557e2ce3fa49b1cd296243f0d45adf0e11
sha256: 66bd869fa91f2ce6071e7ae3907d3a9672dcaf2e4499291524e225888d756739
sha512: 2e285b9493f0c9e3cfedb50a08e5f449e159485e24a7fcb676b0c8cd2efb5e417774199741ad6d10baaeed4fc8507ead8c405b8fd74422b91ffb34fa926a3506
ssdeep: 96:Zuz4E254C2s4y2emZNYrhb0ouMWsWrvQ9TcE2NYlnlYJnLrL0KffvzBEGnv16cRt:Zui+mrqo5WFoGVQnlYJLrLTji7cDN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F8E1B81667F14275CE5B07772CB302411B73EA05CE67EB6F0888A3E5C9E31654A62E72
sha3_384: 29cb31016f7dc4ade99e5e10e2d4e90949f6dac255d7fdfb5cb9a60d187221e0b20a75dd332a8cc0a44e57746d8e4ffc
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-02-16 01:21:39

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Mozilla.exe
LegalCopyright:
OriginalFilename: Mozilla.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL:Agent-CWF [Trj] also known as:

BkavW32.FamVT.CerbuPKG.Trojan
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.51606
FireEyeGeneric.mg.5152d559d85e947a
CAT-QuickHealTrojan.Mogoogwi.A3
McAfeeTrojan-FMGK!5152D559D85E
MalwarebytesBackdoor.Agent.MSIL
VIPREGen:Variant.Barys.51606
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004be57a1 )
AlibabaTrojan:MSIL/Mogoogwi.556027b2
K7GWTrojan ( 004be57a1 )
Cybereasonmalicious.9d85e9
VirITTrojan.Win32.Generic.BAMF
CyrenW32/S-f2a4b9c7!Eldorado
SymantecTrojan Horse
ESET-NOD32MSIL/Agent.QIF
APEXMalicious
ClamAVWin.Malware.Barys-6804071-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.51606
NANO-AntivirusTrojan.Win32.Agent.dzsvxi
SUPERAntiSpywareBackdoor.Bot/Variant
AvastMSIL:Agent-CWF [Trj]
TencentTrojan.MSIL.Agent.hk
TACHYONTrojan/W32.DN-Agent.7168.AL
SophosTroj/MSIL-CWS
F-SecureTrojan.TR/Mogoogwi.qifa
DrWebTrojan.Siggen7.31585
ZillyaTrojan.Agent.Win32.525695
TrendMicroWORM_MOGOOGWI.SMHA
McAfee-GW-EditionBehavesLike.Win32.Trojan.zt
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Barys.51606 (B)
IkarusTrojan-Dropper.MSIL
GDataGen:Variant.Barys.51606
JiangminTrojan.Generic01.a
GoogleDetected
AviraTR/Mogoogwi.qifa
Antiy-AVLTrojan/MSIL.Mogoogwi
XcitiumTrojWare.MSIL.Agent.QIF@6kzu82
ArcabitTrojan.Barys.DC996
ViRobotTrojan.Win32.Agent.7168.FI
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:MSIL/Mogoogwi.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zusy.R154407
BitDefenderThetaGen:NN.ZemsilF.36250.am0@aeztyso
ALYacGen:Variant.Barys.51606
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallWORM_MOGOOGWI.SMHA
RisingTrojan.Mogoogwi!1.A1A3 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.QIF!tr
AVGMSIL:Agent-CWF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL:Agent-CWF [Trj]?

MSIL:Agent-CWF [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment