Threat Database Trojans Trojan.MSIL.Agent.VVF

Trojan.MSIL.Agent.VVF

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 6,433
Threat Level: 80 % (High)
Infected Computers: 97
First Seen: February 3, 2025
Last Seen: September 3, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.VVF on your system indicates a potential security threat that requires immediate attention. This detection name suggests a type of Trojan horse malware, which is designed to deceive users by appearing as legitimate software while secretly performing malicious activities. Understanding the nature of this threat and taking appropriate steps to remove it is crucial to protecting your computer and sensitive information.

What Is Trojan.MSIL.Agent.VVF?

Trojan.MSIL.Agent.VVF is identified as a Trojan-type threat, which implies it is a malicious program that can cause harm to your computer system. Trojans are known for their ability to disguise themselves as useful applications, making them difficult to detect without proper security software. The ".MSIL" part of the name suggests that this malware is written in Microsoft Intermediate Language, which is a platform-agnostic intermediate representation of the .NET Framework and Common Language Infrastructure. This allows the malware to potentially run on any system that supports .NET, making it versatile and dangerous.

How Trojan.MSIL.Agent.VVF Operates

Like other Trojans, Trojan.MSIL.Agent.VVF is likely designed to operate stealthily, aiming to remain undetected on the infected system for as long as possible. It may exploit vulnerabilities in software or use social engineering tactics to trick users into installing it. Once installed, it could perform a variety of malicious activities, such as stealing sensitive information (like login credentials or financial data), installing additional malware, or providing unauthorized access to the infected computer. The exact operations of Trojan.MSIL.Agent.VVF can vary, but its primary goal is to compromise the security and integrity of the infected system.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Agent.VVF infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow system performance, or programs starting automatically without your permission. You might also notice changes in your browser settings or the appearance of unfamiliar programs and icons. In some cases, the malware might consume system resources, leading to crashes or freezes. Being vigilant about these symptoms can help in early detection and removal of the malware.

How to Remove Trojan.MSIL.Agent.VVF

  1. Boot your computer in Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process and allow you to download necessary tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to effectively detect and remove Trojan.MSIL.Agent.VVF.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are not needed.
  4. Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that all components of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Agent.VVF requires careful and systematic steps to ensure that all malicious components are eliminated from your system. It's essential to stay informed about malware threats and to maintain up-to-date security software to protect against future infections. Regularly backing up important data and being cautious when downloading software or clicking on links can also help prevent malware infections. By understanding the risks and taking proactive measures, you can significantly reduce the likelihood of your computer being compromised by threats like Trojan.MSIL.Agent.VVF.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.VVF
Signature status: No Signature

Known Samples

MD5: 1209962ff5b906e61e370dd4657527f2
SHA1: f83067783396721fb50b6d764d4c228bed1a6d4d
SHA256: C26806F9D67D651EFFD50D40F4F275AC27DEF9F1EE31AE1F8C289D3ED16FB150
File Size: 486.91 KB, 486912 bytes
MD5: 6dee6a8cc89a0a00a43db074535803d5
SHA1: 9582354ec1b77e62453d4ac68c0c686e25dd9e08
SHA256: 8983AC6BA515D20C49A2482C57500B02376A088E057B7B3F9F8E7618EAEB28E2
File Size: 2.41 MB, 2409472 bytes
MD5: aeb91d5371bf9af7bf73bf4f6d98381f
SHA1: f6dc981ed012428f5398096ea0dde72aeee4e349
SHA256: 24AA36005806B28E46E0D4DD434B80B011E0054B61DC67292B859CB5F7F05330
File Size: 3.55 MB, 3554304 bytes
MD5: 6b31d6f8e00d3b18c0c72aa186623cf8
SHA1: ef3c2b332ea9668a95f59cfa7b89d7c8ae0d116d
SHA256: 4CEB8804D5998FEE1E9845250CA40754D616A68C1D0EED09C2239A48B2C642FE
File Size: 2.44 MB, 2439168 bytes
MD5: c66793089feddb6184ac8c2b650ebcc0
SHA1: fe4e3a12bb6e8c3e0ff419aa65c726f6466f28f4
SHA256: 4399E23D23135BCB6A2CAE35D3D212ED007EDA1FA27C363BFD62E0AA3D46D7B3
File Size: 4.66 MB, 4661248 bytes
Show More
MD5: ca3c47dbe417494a0ef127f99cfbcd42
SHA1: 38ac4acee5044c4f2f3c06c01d0186a56eb633f3
SHA256: 4A677A34456D8A9A033252A3A77E7C36E25C1B9092333B357BFD016C3A31004B
File Size: 944.67 KB, 944672 bytes
MD5: 5b475937e8af9749c0c4b986573bd9f3
SHA1: eacb43b68bc76552e8568aa30062a9194b12286a
SHA256: 05050FA330B593AC5E3B71E08EEE27A41E077B5686FFECDC517D063086D3C370
File Size: 1.83 MB, 1827328 bytes
MD5: 7dfd536f80ccbdda5428e0be995c7fb6
SHA1: 3ab35ff9c72e58e13d6336a4363fb631cfd76fd7
SHA256: 1B9D3D2169740E3C51BBC296883D3EBCA91B373C5C0FA861EAB36F1E5DBE9179
File Size: 3.77 MB, 3768352 bytes
MD5: 03a0f2ad16c7796058141d32c3154f38
SHA1: 33c4def2edb751f37eaa0c4026eba29c4876218f
SHA256: 4D81423A8E96E54566504946A6BFD500F47D0FC0D57C874AFD2CFD1B517AE34D
File Size: 3.69 MB, 3691008 bytes
MD5: 7cba34386c4a0802a7b8c945572e79b8
SHA1: 8f49b4cfacdf5903352aa9b9d9e6d96ba90b6168
SHA256: 3E1AE4D08610C49E2E43E1149A428846C7C98DA313C22772EE95B65AE20B9A55
File Size: 1.26 MB, 1259520 bytes
MD5: 2d832a62a14b3943b4236cd5137e29a4
SHA1: 9e39466267733bf9301d4bc35b1139ea5b8ba26f
SHA256: 4C80940B8A4AF46B4A8B1F55548D36F779420E41F02A4B374E0BA49AA9E3FA16
File Size: 701.95 KB, 701952 bytes
MD5: d2ae7b970dec300098ac02e4b7ee05b4
SHA1: 1f2defd0ed25cfee37e65d79dfce6183d0901091
SHA256: 2F0C5AC3B8EE5DB0A87C48C3027ACA05AD5D7A4285B396D1B19CA558B35DAB35
File Size: 3.85 MB, 3854848 bytes
MD5: c7394bf4a432b064a5f477d17de1e26c
SHA1: 69931294ed5bd10b93691716a22da7af25b018c4
SHA256: 00AFFC6D3CBEB15C2C1E5DC6AE704012F17B7F7CEC801A7FA39259D63551AC61
File Size: 5.06 MB, 5064224 bytes
MD5: 7a817e39a30a46c515965a2ae0e64e8c
SHA1: 3f8ebcf23d18e805a1ff6949e17c9ed0f9230abe
SHA256: 8B094BD1993F2BC690B5A7602DF90F3B662AEC307691AD865706B74D0760B02A
File Size: 3.71 MB, 3713024 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 3.0.0.0
  • 2.1.0.0
  • 1.0.0.1
  • 1.0.0.0
Comments xiaomiauth.orh
Company Name
  • Dream Rust * Sylphietta
  • SummerMod
  • UpdaterVB6
  • xiaomiauth.orh
File Description
  • BWContextHandler
  • CompanyBooster
  • DreamMod
  • ElysiumExe
  • FalconFRP
  • GENPROLOGIN
  • Mod
  • SummerMod
  • TSM_Tool_GSMINDIAN
  • UpdaterVB6
Show More
  • WindowsFormsApp1
  • xiaomiauth.orh
File Version
  • 3.0.0.0
  • 2.1.0.0
  • 2.0.1.0
  • 1.0.0.1
  • 1.0.0.0
Internal Name
  • Astralis1.dll
  • Auth.exe
  • COMPANY.dll
  • DreamMod.dll
  • ElysiumExe.exe
  • FalconFRPTool_V1.0.0.1.exe
  • GENPROLOGIN.exe
  • MaxTech Server.exe
  • Rename Me - Unbranded.exe
  • SummerMod.dll
Show More
  • TSM_Tool_GSMINDIAN.exe
  • UpdaterVB6.dll
Legal Copyright
  • Copyright © 2024
  • Copyright © 2025
  • Copyright © 2026
Original Filename
  • Astralis1.dll
  • Auth.exe
  • COMPANY.dll
  • DreamMod.dll
  • ElysiumExe.exe
  • FalconFRPTool_V1.0.0.1.exe
  • GENPROLOGIN.exe
  • MaxTech Server.exe
  • Rename Me - Unbranded.exe
  • SummerMod.dll
Show More
  • TSM_Tool_GSMINDIAN.exe
  • UpdaterVB6.dll
Product Name
  • BWContextHandler
  • CompanyBooster
  • DreamMod
  • ElysiumExe
  • FalconFRP
  • GENPROLOGIN
  • Mod
  • SummerMod
  • TSM_Tool_GSMINDIAN
  • UpdaterVB6
Show More
  • WindowsFormsApp1
  • xiaomiauth.orh
Product Version
  • 3.0.0.0
  • 2.1.0.0
  • 2.0.1
  • 1.0.0.1
  • 1.0.0.0
  • 1.0.0

File Traits

  • .NET
  • 00 section
  • 2+ executable sections
  • Agile.net
  • dll
  • Fody
  • HighEntropy
  • ntdll
  • RijndaelManaged
  • x64
Show More
  • x86

Block Information

Similar Families

  • MSIL.Agent.VVF

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134127142200690859.5076.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_dwl0olr5.yoi.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_dx3ri4ny.0rx.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\autb79d.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\autb82a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\guardian_src_1bdc4e57616d494f8c7746867f21b4b1.cs Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\guardian_src_466a61b761fc4e3a9df750a421b6183c.cs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\guardian_src_5cebd16bb1b94be6ae5b0bbd98a25280.cs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\guardian_src_e7ccc59cd6614f98a671b376dc3af842.cs Generic Write,Read Attributes
c:\users\user\downloads\modified_scripts.ps1 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\modified_scripts.ps1 Generic Write,Read Attributes
c:\users\user\downloads\modified_scripts.ps1 Synchronize,Write Attributes
c:\users\user\downloads\mohamed_soft_kirin.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\downloads\mohamed_soft_kirin.exe Generic Write,Read Attributes
c:\users\user\downloads\mohamed_soft_kirin.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ꉭ䮦仚ǜ RegNtPreCreateKey
HKCU\software\xtrial::start 潗㆜裞 RegNtPreCreateKey
HKCU\software\xtrial::end 꽗愳㵦裞 RegNtPreCreateKey
HKCU\software\xtrial::days  RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 싑掅ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �E���� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe m�DT�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n �v��(�1`1�1HO@V�_�zk`{b��P�������������m�Ù�����$წ���=�SB1_T�Vw���%�������AE��D��&��$���L RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 䎰瞎㰁ǝ RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • CheckRemoteDebuggerPresent
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread

26 additional items are not displayed above.

Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Network Winsock2
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • setsockopt
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory

Shell Command Execution

"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Bcqllmnm\AppData\Local\Temp\f83067783396721fb50b6d764d4c228bed1a6d4d_0000486912.exe" "C:\Users\Bcqllmnm\AppData\Local\Temp\guardian_src_e7ccc59cd6614f98a671b376dc3af842.cs"
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Arfqkkxx\AppData\Local\Temp\f6dc981ed012428f5398096ea0dde72aeee4e349_0003554304.exe" "C:\Users\Arfqkkxx\AppData\Local\Temp\guardian_src_466a61b761fc4e3a9df750a421b6183c.cs"
powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File "c:\Users\user\downloads\Modified_Scripts.ps1"
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Npvydebq\AppData\Local\Temp\3ab35ff9c72e58e13d6336a4363fb631cfd76fd7_0003768352.exe" "C:\Users\Npvydebq\AppData\Local\Temp\guardian_src_5cebd16bb1b94be6ae5b0bbd98a25280.cs"
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Yhvduayc\AppData\Local\Temp\3f8ebcf23d18e805a1ff6949e17c9ed0f9230abe_0003713024.exe" "C:\Users\Yhvduayc\AppData\Local\Temp\guardian_src_1bdc4e57616d494f8c7746867f21b4b1.cs"