Threat Database Trojans Trojan.MSIL.Agent.JJ

Trojan.MSIL.Agent.JJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,127
Threat Level: 80 % (High)
Infected Computers: 81
First Seen: May 11, 2024
Last Seen: July 2, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.JJ indicates that your system has been compromised by a potentially malicious program. This type of threat is typically designed to allow unauthorized access to your computer, steal sensitive information, or disrupt system operations. It is essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.MSIL.Agent.JJ?

Trojan.MSIL.Agent.JJ is a type of Trojan horse malware, which is a broad category of threats that disguise themselves as legitimate programs. The name "Trojan.MSIL.Agent.JJ" suggests that it is a malicious program written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic language used by the .NET Framework. However, without more specific information, it is difficult to determine the exact nature and behavior of this particular threat.

How Trojan.MSIL.Agent.JJ Operates

Trojan horses like Trojan.MSIL.Agent.JJ often operate by exploiting vulnerabilities in software or using social engineering tactics to trick users into installing them. Once installed, they can create backdoors, allowing remote access to your system, or engage in other malicious activities such as data theft, keystroke logging, or spamming. The specific operations of Trojan.MSIL.Agent.JJ are unknown, but it is likely that it is designed to remain stealthy and avoid detection.

Symptoms of Infection

Systems infected with Trojan.MSIL.Agent.JJ may exhibit a range of symptoms, including unusual network activity, slowed system performance, or unexplained changes to system settings. You may also notice that your browser is being redirected to unwanted websites, or that you are receiving unexpected pop-ups or spam messages. However, some Trojans can operate without displaying any noticeable symptoms, making them difficult to detect without the use of specialized security software.

  • Unexplained changes to system settings or files
  • Slow system performance or crashes
  • Unwanted pop-ups, spam, or redirected browsing
  • Unusual network activity or unknown connections

How to Remove Trojan.MSIL.Agent.JJ

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the infection.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.MSIL.Agent.JJ requires a combination of technical expertise and the use of specialized security software. By following the steps outlined above and taking proactive measures to secure your system, you can help prevent future infections and protect your sensitive information. Remember to always be cautious when installing new software, avoid suspicious links or email attachments, and keep your operating system and security software up to date to minimize the risk of malware infections.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.JJ
Signature status: No Signature

Known Samples

MD5: f9c43e50a3d1532b853fb00d8c8ffdad
SHA1: 1057b9f805470cf67dfe98f0404abb25b777fd0d
SHA256: 11B84C05297B0CACB16C0F1AD5C0D7C24E767CCA9F363096CDA85CC94239A8F0
File Size: 34.82 KB, 34816 bytes
MD5: 16aa0d12298c527df4ec7381d1e2fa82
SHA1: fa4aadd65db72c6cb80fe23132c7c69d70c9e8f9
SHA256: 6BFA3A35B5B56A511712BB86F5B5FCF47432765AFF5FEC7D318F04365F21F70B
File Size: 64.70 KB, 64696 bytes
MD5: 3b49ce4a08a4f3876b691c9a7a5e6c3a
SHA1: ae5649feb197ac65cff393be1c22e77bd710cb38
SHA256: BB57059B8565739F8388908CEB75B4D454082991E19D410F6E904A49E5574349
File Size: 24.58 KB, 24576 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • DGTLockUnlockDesktop.exe
  • DISWIPM.exe
  • SSMSO Network Tool.exe
Original Filename
  • DGTLockUnlockDesktop.exe
  • DISWIPM.exe
  • SSMSO Network Tool.exe
Product Version 0.0.0.0

Digital Signatures

Signer Root Status
Gary Hickinson (Admin) Gary Hickinson (Admin) Self Signed

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 34
Potentially Malicious Blocks: 6
Whitelisted Blocks: 28
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.JJ
  • MSIL.FakeMS.HF
  • MSIL.FakeMS.LA
  • MSIL.FakeMS.Q
  • MSIL.FakeMS.QA
Show More
  • MSIL.FakeMS.QN

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134213163063602176.4756.defaultappdomain.1057b9f805470cf67dfe98f0404abb25b777fd0d_0000034816 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134225717751173067.9904.defaultappdomain.fa4aadd65db72c6cb80fe23132c7c69d70c9e8f9_0000064696 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134238422110612931.4292.defaultappdomain.ae5649feb197ac65cff393be1c22e77bd710cb38_0000024576 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_5ryzfrdb.x4y.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_eis1g42v.do3.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_ghghhbm4.3j1.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_my55sh1p.3js.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_r1igxm2b.2d4.ps1 Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\__psscriptpolicytest_wa422ip0.mna.psm1 Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady

3 additional items are not displayed above.

User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Related Posts

Trending

Most Viewed

Loading...