Threat Database Trojans Trojan.MSIL.Agent.GT

Trojan.MSIL.Agent.GT

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 37
First Seen: March 4, 2023
Last Seen: September 16, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.GT on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operations, symptoms, and most importantly, the steps to remove it from your computer.

What Is Trojan.MSIL.Agent.GT?

Trojan.MSIL.Agent.GT is identified as a Trojan-type threat, which means it is a malicious program designed to infiltrate your system by disguising itself as legitimate software. The name suggests it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic, CPU-independent intermediate representation for the .NET Common Language Infrastructure. This type of malware can be particularly dangerous as it can perform a wide range of malicious activities once inside your system.

How Trojan.MSIL.Agent.GT Operates

Once Trojan.MSIL.Agent.GT infects a system, it can operate in various ways, depending on its design and the intentions of its creators. Commonly, Trojans are used to gain unauthorized access to a victim's system, allowing hackers to steal sensitive information, install additional malware, disrupt system operation, or use the infected computer as part of a botnet for malicious activities such as spamming or DDoS attacks. The specific operations of Trojan.MSIL.Agent.GT can vary, but its primary goal is to compromise the security and integrity of the infected system.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, there are several symptoms that might indicate the presence of Trojan.MSIL.Agent.GT or similar malware on your system. These include, but are not limited to, unexpected changes in system performance, such as slow operation, frequent crashes, or unusual network activity. You might also notice new, unfamiliar programs or icons on your desktop, changes in your browser settings, or the appearance of unwanted pop-ups and advertisements. Any of these signs should prompt you to take immediate action to secure your system.

How to Remove Trojan.MSIL.Agent.GT

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Perform a Full Scan with a Reputable Anti-Malware Tool: Utilize a trusted anti-malware program, such as SpyHunter, to scan your system thoroughly. This can help identify and remove the Trojan and any other malware that might be present.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you do not recognize or that were installed around the time your system became infected.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, and Edge to their default settings can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot and Re-scan: After taking the above steps, restart your computer and perform another scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.MSIL.Agent.GT requires careful and immediate action to prevent further damage to your system and protect your personal data. By understanding the nature of this threat and following the steps outlined in this report, you can effectively eliminate the malware and secure your computer. Remember, prevention is key; keeping your operating system, software, and security tools up to date, along with practicing safe browsing habits, can significantly reduce the risk of future infections.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.GT
Signature status: No Signature

Known Samples

MD5: 5095e4d69c20388b43db27d6be8c4422
SHA1: c08c27e715a137ee03664f011338efcb61d0ae77
SHA256: 6C04AF3C5ED00E6590ACB77581FC5C8EC522BF2A55CCB364D104D464CE85D38E
File Size: 447.49 KB, 447488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description WormJoiner
File Version 1.0.0.0
Internal Name Stub.exe
Legal Copyright Copyright © 2022
Original Filename Stub.exe
Product Name WormJoiner
Product Version 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 536
Potentially Malicious Blocks: 520
Whitelisted Blocks: 0
Unknown Blocks: 16

Visual Map

x ? ? x x x x ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\mofeehoiie\c08c27e715a137ee03664f011338efcb61d0ae77_0000447488 Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Related Posts

Trending

Most Viewed

Loading...