Threat Database Trojans Trojan.MSIL.Agent.GS

Trojan.MSIL.Agent.GS

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 23,281
Threat Level: 80 % (High)
Infected Computers: 11
First Seen: February 22, 2023
Last Seen: May 14, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.GS on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.MSIL.Agent.GS?

Trojan.MSIL.Agent.GS is a type of Trojan horse malware that can infect your computer through various means, such as downloading malicious software, opening suspicious email attachments, or visiting compromised websites. The name "Trojan.MSIL.Agent.GS" suggests that it is a Trojan-type threat, but the specific characteristics and behaviors of this malware are not well-defined without additional context.

How Trojan.MSIL.Agent.GS Operates

Once installed, Trojan.MSIL.Agent.GS can operate in the background, potentially allowing unauthorized access to your computer, stealing sensitive information, or using your system as a botnet to conduct malicious activities. It may also download and install additional malware, creating a complex and challenging situation to resolve. The exact mechanisms of how Trojan.MSIL.Agent.GS operates are not specified, but it's clear that it poses a significant risk to your computer's security and your personal data.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Agent.GS infection can vary, but common indicators include slow system performance, unexpected pop-ups, and unfamiliar programs or icons on your desktop. You may also notice that your browser is redirecting to unwanted websites, or that your antivirus software is disabled or not functioning correctly. In some cases, you may not notice any symptoms at all, which is why regular system scans and monitoring are crucial for detecting and removing malware like Trojan.MSIL.Agent.GS.

How to Remove Trojan.MSIL.Agent.GS

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more straightforward removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs associated with Trojan.MSIL.Agent.GS.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Agent.GS from your computer requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good computing habits, such as regularly updating your operating system and antivirus software, you can help prevent future infections and keep your computer and personal data safe. Remember to always be cautious when downloading software or opening email attachments from unknown sources, and never hesitate to seek professional help if you're unsure about how to proceed with removing a malware infection.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.GS
Signature status: No Signature

Known Samples

MD5: 1d77c076479b28dc55d7f36107479fdc
SHA1: f808a133decf2eabe62c05387622905bbb12134c
SHA256: 7BCB554DFEE87E9BF2862D3EDD7CD3A135202B17446CFF4B07CB8D6C8F178ADF
File Size: 86.02 KB, 86016 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 6.0.0.0
Comments (本产品基于Foxtable设计)
File Version 2022.07.18.1209
Internal Name 辽宁报考大数据系统鲲鹏赠送版.exe
Original Filename 辽宁报考大数据系统鲲鹏赠送版.exe
Product Version 2022.07.18.1209

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 6
Potentially Malicious Blocks: 1
Whitelisted Blocks: 5
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • BadJoke.I
  • MSIL.Agent.DYA
  • MSIL.Agent.EUE
  • MSIL.Agent.KPSC
  • MSIL.Bulz.TJ
Show More
  • MSIL.Bulz.X

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �mv�jg �� �v xy ��T������%����Bx�<#��&� &�-(�(X�(�)�`*J*9*�"-!R1�1HO5,]@V�A��G�IH[uH�pJ��N$N�U_*X�.X�_�zb"hc�wc�zh�ri��j�bk`k�ql(�lR q�XrnJr�BsU�tǤu�~vy�w�ny�9 RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱嗃馐ʊ耀Ś隞̃樁耀꧌ʅ٧ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
Show More
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

(NULL) c:\users\user\downloads\LNdsjKPzs.exe fox
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 836

Related Posts

Trending

Most Viewed

Loading...