Threat Database Trojans Trojan.MSIL.Agent.FRT

Trojan.MSIL.Agent.FRT

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: December 14, 2024
Last Seen: December 6, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.FRT indicates that your system has been compromised by a potentially malicious program. This report aims to provide you with general guidance on understanding and removing the threat. It's essential to note that the specific characteristics of Trojan.MSIL.Agent.FRT may vary, and the information provided here is based on general knowledge of Trojan-type threats.

What Is Trojan.MSIL.Agent.FRT?

Trojan.MSIL.Agent.FRT is a type of malware that can compromise the security and integrity of your system. The term "Trojan" refers to a broad category of malicious programs that can disguise themselves as legitimate software, allowing them to infiltrate systems without being detected. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic language used by the.NET Framework. The "Agent.FRT" part of the name is likely a specific identifier assigned by the security software that detected the threat.

How Trojan.MSIL.Agent.FRT Operates

Trojan-type threats, including Trojan.MSIL.Agent.FRT, typically operate by exploiting vulnerabilities in software or human behavior to gain unauthorized access to a system. Once inside, the malware can perform a variety of malicious activities, such as stealing sensitive information, installing additional malware, or providing a backdoor for remote access. The exact operations of Trojan.MSIL.Agent.FRT may depend on its specific design and purpose, but it's likely that it can cause significant harm to your system and data.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Agent.FRT infection can vary, but common indicators include unusual system behavior, slow performance, and unexpected changes to system settings or files. You may also notice suspicious network activity, such as unusual outgoing connections or data transfers. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without the aid of security software.

How to Remove Trojan.MSIL.Agent.FRT

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. This can help detect and remove the Trojan.MSIL.Agent.FRT malware and any related components.
  3. Uninstall any suspicious programs or applications that may be related to the malware. Be cautious when doing so, as some legitimate programs may be mistakenly identified as malicious.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or settings that may have been installed by the malware.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed. It's essential to verify that the threat has been eliminated to prevent reinfection.

Conclusion

The detection and removal of Trojan.MSIL.Agent.FRT require careful attention to system security and integrity. By following the steps outlined in this report and maintaining good security practices, such as keeping software up-to-date and using reputable anti-malware tools, you can help protect your system from future threats. Remember to always be cautious when downloading and installing software, and never click on suspicious links or attachments from unknown sources.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.FRT
Signature status: No Signature

Known Samples

MD5: 560505643d101f6ef1461d957cac982d
SHA1: 33386a7d23677c0481e15879a7bab49332a15c33
SHA256: 2ED7B651E973EA14128A19AB309355D79409A9D1E2B9009BE5FF179A6EB9408C
File Size: 475.14 KB, 475136 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name MitaPointer.exe
Original Filename MitaPointer.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 2
Potentially Malicious Blocks: 2
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.FRT

Files Modified

File Attributes
c:\programdata\simplecursormaker\cursor\alternate.cur Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\busy.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\diagonal1.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\diagonal2.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\handwriting.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\help.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\horizontal.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\install.inf Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\link.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\move.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\programdata\simplecursormaker\cursor\normal.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\person.cur Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\pin.cur Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\precision.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\text.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\unavailable.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\vertical.ani Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\simplecursormaker\cursor\working.ani Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ���ރMVs}kP~��1��e���1��ie��r � RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
Show More
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

runas C:\Windows\System32\InfDefaultInstall.exe C:\ProgramData\SimpleCursorMaker\Cursor\install.inf

Related Posts

Trending

Most Viewed

Loading...