Threat Database Trojans Trojan.MSIL.Agent.AIC

Trojan.MSIL.Agent.AIC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 23,029
Threat Level: 80 % (High)
Infected Computers: 211
First Seen: November 12, 2022
Last Seen: May 6, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.AIC indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to infiltrate and damage your computer, often without your knowledge or consent. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further harm.

What Is Trojan.MSIL.Agent.AIC?

Trojan.MSIL.Agent.AIC is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or useful programs. The name "Trojan.MSIL.Agent.AIC" suggests that it is written in Microsoft Intermediate Language (MSIL) and may be related to other Agent-type Trojans. However, without more specific information, it is difficult to determine the exact characteristics or intentions of this particular threat.

How Trojan.MSIL.Agent.AIC Operates

Trojan horses like Trojan.MSIL.Agent.AIC typically operate by exploiting vulnerabilities in your system or by tricking you into installing them. Once installed, they can perform a variety of malicious activities, such as stealing sensitive information, installing additional malware, or providing unauthorized access to your system. They may also attempt to evade detection by using various techniques, such as code obfuscation or anti-debugging methods.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Agent.AIC infection can vary, but common signs include slow system performance, unexpected crashes or freezes, and unusual network activity. You may also notice unfamiliar programs or icons on your system, or receive unexpected pop-ups or alerts. In some cases, you may not notice any symptoms at all, which is why regular system scans and monitoring are essential for detecting and removing threats like Trojan.MSIL.Agent.AIC.

How to Remove Trojan.MSIL.Agent.AIC

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be related to the Trojan.MSIL.Agent.AIC infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.MSIL.Agent.AIC from your system requires careful attention to detail and a thorough understanding of the threat. By following the steps outlined above and using reputable anti-malware tools, you can help to ensure that your system is clean and secure. Remember to always be cautious when installing new programs or clicking on links, and to regularly scan your system for signs of infection. By taking these precautions, you can help to protect your system and your sensitive information from threats like Trojan.MSIL.Agent.AIC.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.AIC
Signature status: No Signature

Known Samples

MD5: 31b12955cec189bf652560a93e344ac3
SHA1: 9513586a15e5ebbea23c28e9f7d118dbad2f900c
File Size: 8.19 KB, 8192 bytes
MD5: d61c4e56bf23e664bc2d8b194e2ba9eb
SHA1: 85634090712e91512e67433a808e22e2985de2c4
SHA256: 95232E4AE515D75AC3A641514B55279EEBF2B1B56FB589367E045D3F7BC6C910
File Size: 8.70 KB, 8704 bytes
MD5: 89e44ab047e6427e255eccf26df62b0e
SHA1: 5e41c6557847cac2a09ee4051a333330fb3acb6b
SHA256: 6168BDC8B0DE7E2F8926C0B9786D17571AD3327F5BF2A3B82D1D460F4ABBFB68
File Size: 8.19 KB, 8192 bytes
MD5: 0a850236f8bed3b60d80ec1b7ecd39d8
SHA1: f8cfc146fd7030f2fee3d3e2e183fcfe9dc8f079
SHA256: 9E0AD12160664CE7453C1557E44A75469CBFAAFCBB71D2F89F7334A6E594444A
File Size: 8.70 KB, 8704 bytes
MD5: b98e86233dbb16cbbae46830c144007d
SHA1: dac4f9f09669883dde244795bfcd1a719747388c
SHA256: 056655A76B7E4B8648E45C7F77F6B4401031377CCEC82CD400EC64B255758071
File Size: 8.70 KB, 8704 bytes
Show More
MD5: 31d0b742b99ea9ade9f326c8f41e54c0
SHA1: e570ab9973d1d7b8d8a912a765a4d02490442401
SHA256: B06923A238BDB2F675F16E9761A7DB3B1BF89F6FF03ECA172222DBB7DD9C71EA
File Size: 10.75 KB, 10752 bytes
MD5: 86830c55c0461a0d2bea41bf2bc37599
SHA1: 4c6ec3d340d4679b6a1dfca8f761d8b890b82378
SHA256: 89325D18D4ECE33334775C84AD7E69778262768437BE32F960F2C26C5928931C
File Size: 8.70 KB, 8704 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • build-uninstaller.exe
  • forskreshivanie-uninstaller.exe
  • latest-uninstaller.exe
  • miner-uninstaller.exe
  • NetLimiter-uninstaller.exe
  • ok-uninstaller.exe
  • y-uninstaller.exe
Original Filename
  • build-uninstaller.exe
  • forskreshivanie-uninstaller.exe
  • latest-uninstaller.exe
  • miner-uninstaller.exe
  • NetLimiter-uninstaller.exe
  • ok-uninstaller.exe
  • y-uninstaller.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • CreateThread
  • Installer Version
  • ntdll
  • x64

Block Information

Total Blocks: 7
Potentially Malicious Blocks: 7
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.AIC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • ReadProcessMemory

Related Posts

Trending

Most Viewed

Loading...