Threat Database Trojans Trojan.MSIL.Downloader.AGC

Trojan.MSIL.Downloader.AGC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,596
Threat Level: 80 % (High)
Infected Computers: 10
First Seen: September 4, 2022
Last Seen: July 4, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.AGC indicates that your system has been compromised by a malicious threat. This type of threat is designed to download and install additional malware on your system, which can lead to a range of problems, including data theft, system crashes, and unauthorized access to your computer. It is essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.MSIL.Downloader.AGC?

Trojan.MSIL.Downloader.AGC is a type of Trojan horse malware that is designed to download and install additional malware on your system. The name "Trojan.MSIL.Downloader.AGC" suggests that it is a downloader Trojan, which means it is designed to download and install other malicious programs. The "MSIL" part of the name refers to the Microsoft Intermediate Language, which is a programming language used by the .NET Framework. This suggests that the malware is written in a .NET language and is designed to run on Windows systems.

How Trojan.MSIL.Downloader.AGC Operates

Trojan.MSIL.Downloader.AGC operates by downloading and installing additional malware on your system. This can happen in a variety of ways, including through exploited vulnerabilities, drive-by downloads, or social engineering tactics. Once the malware is installed, it can communicate with its command and control server to receive instructions and download additional malware. This can lead to a range of problems, including data theft, system crashes, and unauthorized access to your computer.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Downloader.AGC infection can vary, but common signs include slow system performance, unexpected pop-ups and ads, and unfamiliar programs or icons on your desktop. You may also notice that your system is crashing or freezing frequently, or that your antivirus software is detecting and blocking malicious activity. If you suspect that your system has been infected with Trojan.MSIL.Downloader.AGC, it is essential to take immediate action to remove the threat.

How to Remove Trojan.MSIL.Downloader.AGC

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove the malware.
  3. Uninstall any suspicious programs that you have installed recently, as they may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the malware has been fully removed.

Conclusion

Removing Trojan.MSIL.Downloader.AGC requires immediate attention to prevent further damage to your system. By following the steps outlined above, you can remove the malware and prevent future infections. It is also essential to take steps to prevent future infections, including keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading and installing programs from the internet. Remember to always be vigilant and take immediate action if you suspect that your system has been infected with malware.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.AGC
Signature status: No Signature

Known Samples

MD5: 6bc2ac72b99b2df3817487398f0375e8
SHA1: 7bdb244bc48321d788c3ef06ba8506752e58cc86
SHA256: B121E0EA8C4774F83638C4BDFD1C7C59EC3237F5E1C8BE1612228FFCCE954BB4
File Size: 2.33 MB, 2325504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 24.0.0.0
Comments BUSINESS SENDER V.24 BY TIGER VIKRAM
Company Name Tiger Vikram
File Description BUSINESS SENDER V.24 BY TIGER VIKRAM
File Version 24.0.0.0
Internal Name BUSINESS SENDER V.24 BY TIGER VIKRAM.exe
Legal Copyright Copyright © 2024
Original Filename BUSINESS SENDER V.24 BY TIGER VIKRAM.exe
Product Name BUSINESS SENDER V.24 BY TIGER VIKRAM
Product Version 24.0.0.0

File Traits

  • .NET
  • NewLateBinding
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 1,346
Potentially Malicious Blocks: 430
Whitelisted Blocks: 886
Unknown Blocks: 30

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x x x x x 0 x 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x 0 x 0 0 x 0 ? 0 0 0 0 0 0 0 x ? x x x ? ? x ? 0 x 0 0 0 x 0 0 0 0 x x x 0 0 x x x x x x x 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 x 0 0 x x x 0 0 x 0 0 0 x x x x x x x x 0 0 0 x 0 0 x x 0 x x 0 0 ? 0 0 0 0 0 x 0 x 0 0 0 0 ? 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 ? 0 0 0 x 0 0 0 ? 0 0 0 0 ? ? 0 0 x 0 0 0 x x 0 0 0 x 0 0 0 0 0 x x x 0 x x 0 0 x 0 0 0 0 0 x x x x x 0 0 x 0 0 x x x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 x x x x x x x 0 0 x 0 0 x 0 0 0 x x x x x x 0 x x 0 0 0 0 0 0 0 0 x 0 x x x x 0 x x x x x x x x x x x x x x 0 x x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 x x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x x x 0 ? ? x x 0 x 0 x x x x x x x x 0 x 0 x x 0 0 0 0 0 0 0 ? x x ? ? x 0 x 0 0 x x x 0 x 0 0 x x x x 0 x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 0 x 0 0 x x 0 0 0 0 0 x 0 0 x 0 0 0 x x x 0 0 x 0 0 0 x x x x x 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x x x 0 x x x x 0 x 0 x x x x x x x x x x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x ? x x x x x x x x 0 0 x 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x x x x ? 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x ? 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 x ? x x x ? x x x 0 0 0 x x x x x x 0 x 0 x x x x 0 x 0 x x x x x 0 x 0 x ? 0 x x 0 x x x x x x x x x x x 0 0 x x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x 0 0 x 0 0 0 x x 0 0 ? 0 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? x x x ? x x x x x x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x 0 0 0 x 0 0 0 0 0 0 0 x x x x x x 0 0 x 0 0 0 0 0 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x 0 x x 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Downloader.AGC

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...