Threat Database Trojans Trojan.MSIL.Agent.SKJ

Trojan.MSIL.Agent.SKJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,365
Threat Level: 80 % (High)
Infected Computers: 25
First Seen: April 11, 2025
Last Seen: May 27, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.SKJ indicates that a potentially malicious program has been identified on your system. This name suggests it is a type of Trojan, which is a broad category of malware that can perform a variety of harmful actions on an infected computer. Understanding what this detection means and how to address it is crucial for maintaining the security and integrity of your system.

What Is Trojan.MSIL.Agent.SKJ?

Trojan.MSIL.Agent.SKJ, as a detected threat, falls under the umbrella of Trojan horses, which are malicious programs that disguise themselves as legitimate software. The term "Trojan" in the name refers to its ability to deceive users about its true intent, much like the legendary Trojan Horse. These types of malware can be designed to perform a wide range of malicious activities, from stealing sensitive information to disrupting system operations. The "MSIL" part of the name refers to Microsoft Intermediate Language, which is a component of the .NET Framework, suggesting that this malware might be written in a .NET language and could potentially affect systems running Microsoft Windows.

How Trojan.MSIL.Agent.SKJ Operates

Trojan.MSIL.Agent.SKJ, like other Trojans, operates by first gaining unauthorized access to a computer system, often through deception or exploitation of vulnerabilities. Once inside, it can execute a variety of malicious actions, depending on its design. This can include data theft, where it collects and sends sensitive information like passwords, credit card numbers, or personal data back to its creators. It might also install additional malicious software, provide unauthorized access to the system for further malicious activities, or disrupt system operation to cause chaos or demand ransom.

Symptoms of Infection

Identifying a Trojan infection can be challenging because these malware types are designed to be stealthy. However, there are several symptoms that might indicate the presence of Trojan.MSIL.Agent.SKJ or similar malware. These include unusual system behavior, such as unexpected crashes, slow performance, or unfamiliar programs and icons. You might also notice increased network activity without a clear cause, or find that your antivirus software is disabled or fails to update. In some cases, Trojans can lead to the installation of additional malware, which might display more overt symptoms, such as pop-ups, unwanted toolbar installations, or redirects to suspicious websites.

How to Remove Trojan.MSIL.Agent.SKJ

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode loads Windows with a minimal set of drivers and services, making it easier to remove malicious software.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter. Ensure your antivirus software is updated with the latest definitions to improve the chances of detecting and removing the malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed without your consent. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your system and perform another full scan to ensure that the malware has been successfully removed. Repeat the scanning process until no threats are detected.

Conclusion

Dealing with a Trojan.MSIL.Agent.SKJ infection requires careful and immediate action to prevent further damage to your system and protect your personal data. By understanding the nature of this threat and following the removal steps outlined, you can effectively eliminate the malware and secure your computer. Remember, prevention is key; keeping your operating system, software, and antivirus tools up to date, along with practicing safe browsing habits, can significantly reduce the risk of future infections.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.SKJ
Signature status: No Signature

Known Samples

MD5: d6ad39ca94219d734ce4327508d6fedd
SHA1: 97abdca5dddb9fbdf46221810aef825f9e429522
SHA256: AC28BF42EE3912B8FF4EBC2C0745571150C2CBA7B85B540F01FD42AD0AD0CAF2
File Size: 237.43 KB, 237430 bytes
MD5: 90eb57e9e9e3ef30c22020fc8d9ef379
SHA1: 91d1ccbab69951c97d425a9a0395379d532d23b5
SHA256: 98DFA6BFE8EFFEF37EF968A457A495C28E8011127A3B30F689E18CED9A62C9A2
File Size: 15.36 KB, 15360 bytes
MD5: 3917b95380e5100ef2200edfe1b25a10
SHA1: 4b593b61f25d8e9cb40b81e5a25729675884d71c
SHA256: 325B25AABD6E71AFD7C704188E343F0713114591017676B686F183486BFAE5CA
File Size: 16.38 KB, 16384 bytes
MD5: dff10ae2043759d5d5677e9c88ed433b
SHA1: 129b4a2125ff7681a83bfc479c6e59e7abe83450
SHA256: 405DD2D599FC0AFF7F3C275095E1937E67FDEF0BB4E2CBD87533B5383180B121
File Size: 15.87 KB, 15872 bytes
MD5: 82d3bf275e3d2e1d21b8966695172286
SHA1: 61c72c72937d5c7a51301a103177938451972b24
SHA256: F59795FA3BB63421CAB54DAB34625D8A56E81173FD98E79A1E3E2B20846AC6D0
File Size: 15.36 KB, 15360 bytes
Show More
MD5: a9192273f21d993e6a863f2b6243c7c8
SHA1: 5c2784e9d5805403195fe7d4c73d25b7d0bf5ffb
SHA256: A721150BE5DD80DEBAC3095A8967E9CCFBB61539B9947F166704A7643E5D92F7
File Size: 16.38 KB, 16384 bytes
MD5: 26d0900e42381eaf67ccc57acaf256ae
SHA1: 1aedbad935b365a5202f642b53a1b442f4d245c1
SHA256: 055A8EE06CF09B640625A35978B609AF54187D80247E5FC0C466F7E4678F1A22
File Size: 234.90 KB, 234900 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • forklift
  • hotline
  • Jekevo
  • Nepoyu
  • web2
  • webview2
  • _view2
File Version
  • 8.6.6.72
  • 2.5.8.124
  • 1.0.0.0
Internal Name
  • BuildProj.exe
  • Jekevo.exe
  • Nepoyu.exe
  • web2.exe
  • w_view2.exe
Legal Copyright
  • Copyright © 2024
  • Copyright © 2025
  • forklift forklift
  • hotline hotline
Original Filename
  • aplastic.exe
  • BuildProj.exe
  • Jekevo.exe
  • Nepoyu.exe
  • patriarch.exe
  • web2.exe
  • w_view2.exe
Product Name
  • forklift 2.5.8.124
  • hotline 8.6.6.72
  • Jekevo
  • Nepoyu
  • web2
  • webview2
  • _view2
Product Version
  • 8.6.6.72
  • 2.5.8.124
  • 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Similar Families

  • MSIL.Agent.SKF
  • MSIL.Agent.SKJ

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\microsoft.web.webview2.core.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\microsoft.web.webview2.winforms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\microsoft.web.webview2.winforms.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\microsoft.web.webview2.wpf.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\sauce.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\sauce.exe Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\nsl20b.tmp\sauce.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\sauce.exe.config Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl20b.tmp\webview2loader.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\linguistic.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\linguistic.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\linguistic.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\linguistic.exe.config Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\microsoft.web.webview2.core.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\microsoft.web.webview2.winforms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\microsoft.web.webview2.winforms.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\microsoft.web.webview2.wpf.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy4780.tmp\webview2loader.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Rkdswpfm\AppData\Local\Temp\nsl20B.tmp\sauce.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Rkdswpfm\AppData\Local\Temp\nsl20B.tmp\sauce.exe\??\C:\Users\Rkdswpfm\AppData\Local\Temp\nsl20B.tmp\ RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ZwMapViewOfSection
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Shell Command Execution

C:\Users\Rkdswpfm\AppData\Local\Temp\nsl20B.tmp\Sauce.exe ""
C:\Users\Eugugxsi\AppData\Local\Temp\nsy4780.tmp\Linguistic.exe ""

Related Posts

Trending

Most Viewed

Loading...