Threat Database Trojans Trojan.MSIL.Agent.SKH

Trojan.MSIL.Agent.SKH

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,880
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: April 4, 2025
Last Seen: June 24, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.SKH indicates that your system has been compromised by a potentially malicious program. This type of threat is generally categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. Trojans can cause significant harm to your computer and data, making it essential to understand and address the issue promptly.

What Is Trojan.MSIL.Agent.SKH?

Trojan.MSIL.Agent.SKH is a detected threat that suggests your system is infected with a type of malware designed to perform unauthorized actions. The name itself does not specify a known malware family but indicates it's a Trojan-type threat. Trojans are known for their ability to sneak into a system by masquerading as useful software, and once installed, they can open backdoors for remote access, steal sensitive information, or disrupt system operation.

How Trojan.MSIL.Agent.SKH Operates

Understanding how a Trojan operates is crucial for mitigating its effects. Typically, Trojans are spread through various means, including email attachments, infected software downloads, or exploited vulnerabilities in the operating system or applications. Once a Trojan infects a system, it can execute a wide range of malicious activities, from data theft and espionage to using the infected computer as a botnet for distributing spam or launching denial-of-service attacks. The specific actions of Trojan.MSIL.Agent.SKH would depend on its design and the intentions of its creators.

Symptoms of Infection

The symptoms of a Trojan infection can vary widely, depending on the malware's purpose and functionality. Common signs include unexpected changes to system settings, unusual network activity, slow system performance, or the appearance of unwanted software or toolbars in your web browser. In some cases, infections may not exhibit noticeable symptoms, making regular system scans crucial for early detection.

  • Unexplained system crashes or freezes
  • New, unfamiliar icons or programs on your desktop or in your system tray
  • Changes to your browser's homepage or the sudden appearance of pop-up ads
  • Increased network activity when you're not using your internet connection

How to Remove Trojan.MSIL.Agent.SKH

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the Trojan and any associated malware.
  3. Uninstall any recently installed programs that you don't recognize or that were installed around the time the infection was detected.
  4. Reset your web browsers (e.g., Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes.
  5. Reboot your computer and run another full scan with your anti-malware software to ensure that all components of the Trojan have been removed.

Conclusion

The removal of Trojan.MSIL.Agent.SKH requires careful and thorough steps to ensure that all malicious components are eliminated from your system. It's also crucial to adopt preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading software from the internet. By understanding the nature of Trojan threats and taking proactive steps, you can significantly reduce the risk of infection and protect your digital assets.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.SKH
Signature status: No Signature

Known Samples

MD5: d2bfcfbda5498046bf2be83cefc50266
SHA1: 1970af2e1d9c219d7ee105a044225e112668ba32
SHA256: 92FD5DBC9B19C32ADA9C1E0DD443B06770ABE6A03F9DD79C36899213C11E599B
File Size: 26.62 KB, 26624 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Seamless solution that optimizes your security. Powerful utility that coordinates your automation. Seamless platform that enhances your analytics. Seamless solution that optimizes your security. Powerful utility that coordinates your automation. Seamless platform that enhances your analytics. Seamless solution that optimizes your security. Powerful utility that coordinates your automation. Seamless platform that enhances your analytics.
Company Name Akeyic
File Description Cotahi
File Version 1.0.0.0
Internal Name Akeyic.exe
Legal Copyright Copyright © 2025
Original Filename Akeyic.exe
Product Name Cotahi
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 98
Potentially Malicious Blocks: 44
Whitelisted Blocks: 54
Unknown Blocks: 0

Visual Map

0 0 x x x x 0 x x x 0 x 0 0 x x x 0 0 0 0 0 0 x 0 x x x 0 0 0 x 0 x 0 x x 0 0 x x x x 0 0 0 0 0 x 0 x x 0 0 x 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 x x 0 0 x 0 0 0 x x 0 x 0 0 0 x 0 x x 0 0 x x x x 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.SKG
  • MSIL.Agent.SKH

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
Show More
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...