Trojan

Trojan:MSIL/Aggah removal tips

Malware Removal

The Trojan:MSIL/Aggah is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Aggah virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:MSIL/Aggah?


File Info:

name: F56B5D0493C9A866C332.mlw
path: /opt/CAPEv2/storage/binaries/5742ebd53b2b495df0c6bff8ddc17d1726cb8e76e269bd8207b07a0a3ee2b813
crc32: 130DAC62
md5: f56b5d0493c9a866c3329fa3a17a48fb
sha1: 78e5c0ba309b707c3d334b849665287a84ac1aca
sha256: 5742ebd53b2b495df0c6bff8ddc17d1726cb8e76e269bd8207b07a0a3ee2b813
sha512: 01e4816149160b63da56341ab252411f8c1fc418016b4267f42ec8c616bf487bf3026bca413f5df64035a913d7bb54e4c3bbfddcc87722db2d7ec96a2871780a
ssdeep: 3072:81FSsueet4mzPqUBmcclzZn/73J8I5G/q1+VY:81FSZeet4WTmcclzNDJVGysC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F94D353CBD5EC05D6C1403066432FCE2A458DBAB9A5FEA181D0BDDF6079AF7A80A1D3
sha3_384: ed67d258058cbad5fe3cecdc93d0542f7fc503035aa49620c21599ccc9cab34d0403d9a76c58b36a94af8c2830a38721
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-09-12 05:02:53

Version Info:

Translation: 0x0000 0x04b0
Comments: Microsoft Office Update -Microsoft.com | Microsoft® | Site Oficial‎
CompanyName: Microsoft Office Update -Microsoft.com | Microsoft® | Site Oficial‎
FileDescription: Microsoft Office Update -Microsoft.com | Microsoft® | Site Oficial‎
FileVersion: 1231.12312.1.1
InternalName: 2.0 com icone.exe
LegalCopyright: Microsoft Office Update -Microsoft.com | Microsoft® | Site Oficial‎
LegalTrademarks: Microsoft Office Update -Microsoft.com | Microsoft® | Site Oficial‎
OriginalFilename: 2.0 com icone.exe
ProductName: Microsoft Office Update -Microsoft.com | Microsoft® | Site Oficial‎
ProductVersion: 1231.12312.1.1
Assembly Version: 2312.23123.1.1

Trojan:MSIL/Aggah also known as:

LionicTrojan.MSIL.HydraPOS.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.RevetRat.2
CynetMalicious (score: 100)
McAfeeGeneric .qh
MalwarebytesMachineLearning/Anomalous.100%
VIPREGen:Variant.MSILPerseus.162697
SangforTrojan.MSIL.Kryptik.PNG
K7AntiVirusTrojan ( 0053c6af1 )
AlibabaTrojan:MSIL/HydraPOS.b8f2b92d
K7GWTrojan ( 0053c6af1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36662.zm0@aulPDXn
VirITBackdoor.Win32.RevetRat.C
CyrenW32/Trojan.CPG.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Kryptik.PNG
APEXMalicious
KasperskyHEUR:Trojan.MSIL.HydraPOS.gen
BitDefenderGen:Variant.MSILPerseus.162697
NANO-AntivirusTrojan.Win32.HydraPOS.fiapqk
MicroWorld-eScanGen:Variant.MSILPerseus.162697
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan.Hydrapos.Xwhl
EmsisoftGen:Variant.MSILPerseus.162697 (B)
F-SecureHeuristic.HEUR/AGEN.1327289
ZillyaTrojan.HydraPOS.Win32.585
TrendMicroBackdoor.MSIL.REVET.AA
McAfee-GW-EditionGeneric trojan.qh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f56b5d0493c9a866
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILPerseus.162697
JiangminTrojan.MSIL.lmng
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1327289
MAXmalware (ai score=100)
Antiy-AVLGrayWare[APT]/Win32.Hagga
XcitiumMalware@#2deci0nl1x46y
ArcabitTrojan.MSILPerseus.D27B89
ZoneAlarmHEUR:Trojan.MSIL.HydraPOS.gen
MicrosoftTrojan:MSIL/Aggah
GoogleDetected
AhnLab-V3Trojan/Win32.MSIL.C3181648
VBA32TScope.Trojan.MSIL
ALYacTrojan.MSIL.Revetrat
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.MSIL.REVET.AA
RisingMalware.Obfus/MSIL@AI.98 (RDM.MSIL2:cgGfnZ+PA5oZZgO4fCFFsw)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.11684286.susgen
FortinetMSIL/GenKryptik.BUJX!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.a309b7
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Aggah?

Trojan:MSIL/Aggah removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment