Threat Database Trojans Trojan.MSIL.Agent.A

Trojan.MSIL.Agent.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,608
Threat Level: 80 % (High)
Infected Computers: 2,113
First Seen: January 7, 2013
Last Seen: June 1, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.A on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational methods, symptoms of infection, and most importantly, steps to remove it from your system. Understanding the nature of this threat and how it operates is crucial in mitigating its effects and preventing future infections.

What Is Trojan.MSIL.Agent.A?

Trojan.MSIL.Agent.A is identified as a Trojan-type threat. Trojans are malicious programs that can cause significant harm to computer systems. They are designed to allow unauthorized access to the victim's system, enabling the attacker to steal sensitive information, install additional malware, or disrupt system operations. The name "Trojan.MSIL.Agent.A" suggests it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the .NET Framework Common Intermediate Language (CIL). This implies the malware could potentially run on any system that supports .NET, making it versatile and dangerous.

How Trojan.MSIL.Agent.A Operates

Like other Trojans, Trojan.MSIL.Agent.A operates by disguising itself as a legitimate program to gain access to a computer system. Once inside, it can perform a variety of malicious actions, including but not limited to, stealing personal data, downloading additional malware, modifying system settings, or even allowing remote access to the attacker. The specific operations of Trojan.MSIL.Agent.A can vary, but its primary goal is to compromise the security and integrity of the infected system without being detected.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs and icons. Additionally, if your system is being used as a botnet or for other malicious activities, you might notice increased network activity even when you're not using the internet. Recognizing these symptoms early can help in taking prompt action to mitigate the threat.

How to Remove Trojan.MSIL.Agent.A

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to perform removal steps.
  2. Perform a Full Scan with a Reputable Tool: Utilize an anti-malware tool like SpyHunter to scan your system thoroughly. These tools are designed to detect and remove malware, including Trojans like Trojan.MSIL.Agent.A.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or that were installed around the time you suspect the infection occurred.
  4. Reset Your Browsers: If your browsers (Chrome, Firefox, Edge) have been affected, resetting them can help remove unwanted extensions and settings changes made by the malware.
  5. Reboot and Re-scan: After taking the above steps, reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Agent.A requires careful and systematic steps to ensure that all components of the malware are eliminated from your system. By understanding how Trojans operate and following the removal steps outlined, you can protect your system from this and similar threats. It's also crucial to maintain good security practices, including keeping your operating system and software up to date, using strong antivirus programs, and being cautious when opening emails or downloading files from the internet. Preventing infections is always more effective than trying to remove them after the fact.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.A
Signature status: No Signature

Known Samples

MD5: efa8e6f720d4ddad65257b5604aea0e3
SHA1: dc3bcf2fa0090d5481aaaeca43f0ab572cabeee0
SHA256: 2C45C5AB77FBDBE8B4257E35C2D6E6197922C66D4598F6840CF12E5823BA4CB4
File Size: 559.10 KB, 559104 bytes
MD5: adff2d126868f04383b5da93c71c827d
SHA1: 80282eab562657bed281ffb4c41006b49faea6ba
SHA256: 22279D2A874413BA6EB65DF5E1BACD62936769A6EE7EFEDD459190E40FAC1519
File Size: 1.08 MB, 1076224 bytes
MD5: de5256c97603c0245f14c1f5bc05feea
SHA1: aa4d92c5795e2000689a6702ab844e6a365c5dca
SHA256: F2EFC0068F692359C89A564497686DFA913E546F4A1115BB13A21E7308F0B7C1
File Size: 480.26 KB, 480256 bytes
MD5: 1bcc2bea7a774df6716273cb25ae37fd
SHA1: 3cd9294ffec440c2b6cfc9d2c1173140ae79cc8a
SHA256: 59A63DC1C27143919EE4FA96927264B5BF6EC430164C9C9BBB1F9513E517B368
File Size: 580.26 KB, 580264 bytes
MD5: c1299fd813327eb2f3980229739778fb
SHA1: 09118ad81ba8dc370c31caa067e52bac71b9910d
SHA256: D776CE2F8214A62F66FBA5E16479CD5962089553FB194175EE599339D9B4F91A
File Size: 727.55 KB, 727552 bytes
Show More
MD5: 544c9fa15a33d59fc70e9640e93bc9e1
SHA1: db661455882225493fd277b6d9c7be8f59f4601c
SHA256: A11EEECBCEAA857E4B5EC80C2AB78099707EEB20710FC853FDB5992258BFC278
File Size: 114.69 KB, 114688 bytes
MD5: 508ddd425ecb358974481a135ade4821
SHA1: 91aeb74792ab9a3916e8afedf56e7c80c6a68446
SHA256: FAF1EA1830C9231F83486FD9F8B8DC7F5EB9A66BC8622C5B63F738783392BA77
File Size: 2.04 MB, 2041856 bytes
MD5: 1a41b8021edb9882e52104da55b833cc
SHA1: 012bceda65be961833bbe86017b324d44cf0f036
SHA256: 089D2EF356E680E03858CB5D07DDEF50D67922A1AFD1027A62A36399C8993D3A
File Size: 231.42 KB, 231424 bytes
MD5: 92ab9718335a7ee8756f8e63f44bc68e
SHA1: 7879a55bce5b7c42e09d736a1bc9b2f4f3fb337f
SHA256: 2BB03FF00844F0AF613A92E7DB11B58FE20722EDFF3C404CCB5F164E193C1C60
File Size: 229.89 KB, 229888 bytes
MD5: 951241ac4588d8872ab671b024eb4d3f
SHA1: a231b86205f0da889f3d225e3aea897345da9f4e
SHA256: FE917952F59EF27B17B4A5C3EC14C4B95D6B8BF56E33E99E944F649357C732E9
File Size: 177.66 KB, 177664 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 7.9.8.2
  • 1.46.5662.2353
  • 1.0.0.0
Comments
  • Coruscate is a proxy checker with configurable modules
  • NVIDIA Container
Company Name
  • HP
  • Ledger Live Team
  • XG0PQ9B57q1b588c7g35w83U6iWv2eL2W
File Description
  • Coruscate
  • Cv1Tunnel
  • FrostWareInstaller
  • Ledger Live
  • NVIDIA Container
  • service
  • SteamSetup
  • UTJ8pH2KphHFSY2AyBwOrlMiweD4
File Version
  • 2.124.0
  • 2.8.3.7
  • 1.46.5662.2353
  • 1.0.0.0
Internal Name
  • ClientClean.exe
  • Coruscate.exe
  • Cv1Tunnel.exe
  • D:\Software & Daten\Tools\_CLIENT\Downloader\25.09.2016\1.exe
  • FrostWareInstaller.exe
  • Ledger Live
  • service.exe
  • SteamSetup.exe
  • XWormClient.exe
Legal Copyright
  • (C) 2016-2026 NVIDIA Copyright © 2026
  • Copyright killerabgg © 2017
  • Copyright © 2023
  • Copyright © 2025
  • Copyright © 2025 Ledger Live Team
  • Copyright © HP 2024
  • Jua213kCNU2hwl1711W2qrXU3t1DGQnUaha
Legal Trademarks killerabgg
Original Filename
  • ClientClean.exe
  • Coruscate.exe
  • Cv1Tunnel.exe
  • D:\Software & Daten\Tools\_CLIENT\Downloader\25.09.2016\1.exe
  • FrostWareInstaller.exe
  • service.exe
  • SteamSetup.exe
  • XWormClient.exe
Product Name
  • Coruscate
  • Cv1Tunnel
  • FrostWareInstaller
  • i4P0v4o8805W32J24BRND8bfe497bw61Ogx0
  • Ledger Live
  • NVIDIA Container
  • service
  • SteamSetup
Product Version
  • 7.9.8.2
  • 2.124.0.0
  • 1.46.5662.2353
  • 1.0.0.0
Squirrel Aware Version 1

Digital Signatures

Signer Root Status
Avira Operations GmbH DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • .NET
  • big overlay
  • HighEntropy
  • Installer Version
  • NewLateBinding
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 6
Potentially Malicious Blocks: 0
Whitelisted Blocks: 3
Unknown Blocks: 3

Visual Map

0 0 0 ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\service.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\abfpdxoqt.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\tunnel.exe Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::service "C:\Users\Dcvvspvq\AppData\Local\service.exe" RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ﮌꝴǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m$ �vT�����#��&�-(�(X�1�1HO@V�A��H[uH�p_�zb"hk�ql(�{b��P����������������.�m�Ù��gi����$�8წ����j�&MA�=�SB1_B��T�Vw���%����AE�zH��D��&��$���L RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱佗隞̃耀꧌ÓϚ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
Show More
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey

23 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAGetOverlappedResult
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • getaddrinfo
  • inet_addr
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Process Terminate
  • TerminateProcess

Shell Command Execution

"cmd.exe" /c taskkill /im tunnel.exe /f
C:\WINDOWS\system32\taskkill.exe taskkill /im tunnel.exe /f
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 1344

Related Posts

Trending

Most Viewed

Loading...