Trojan.MSIL.Agent.VVF
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 6,433 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 97 |
| First Seen: | February 3, 2025 |
| Last Seen: | September 3, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.MSIL.Agent.VVF on your system indicates a potential security threat that requires immediate attention. This detection name suggests a type of Trojan horse malware, which is designed to deceive users by appearing as legitimate software while secretly performing malicious activities. Understanding the nature of this threat and taking appropriate steps to remove it is crucial to protecting your computer and sensitive information.
Table of Contents
What Is Trojan.MSIL.Agent.VVF?
Trojan.MSIL.Agent.VVF is identified as a Trojan-type threat, which implies it is a malicious program that can cause harm to your computer system. Trojans are known for their ability to disguise themselves as useful applications, making them difficult to detect without proper security software. The ".MSIL" part of the name suggests that this malware is written in Microsoft Intermediate Language, which is a platform-agnostic intermediate representation of the .NET Framework and Common Language Infrastructure. This allows the malware to potentially run on any system that supports .NET, making it versatile and dangerous.
How Trojan.MSIL.Agent.VVF Operates
Like other Trojans, Trojan.MSIL.Agent.VVF is likely designed to operate stealthily, aiming to remain undetected on the infected system for as long as possible. It may exploit vulnerabilities in software or use social engineering tactics to trick users into installing it. Once installed, it could perform a variety of malicious activities, such as stealing sensitive information (like login credentials or financial data), installing additional malware, or providing unauthorized access to the infected computer. The exact operations of Trojan.MSIL.Agent.VVF can vary, but its primary goal is to compromise the security and integrity of the infected system.
Symptoms of Infection
Symptoms of a Trojan.MSIL.Agent.VVF infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow system performance, or programs starting automatically without your permission. You might also notice changes in your browser settings or the appearance of unfamiliar programs and icons. In some cases, the malware might consume system resources, leading to crashes or freezes. Being vigilant about these symptoms can help in early detection and removal of the malware.
How to Remove Trojan.MSIL.Agent.VVF
- Boot your computer in Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process and allow you to download necessary tools.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to effectively detect and remove Trojan.MSIL.Agent.VVF.
- Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are not needed.
- Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
- After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that all components of the malware have been removed.
Conclusion
Removing Trojan.MSIL.Agent.VVF requires careful and systematic steps to ensure that all malicious components are eliminated from your system. It's essential to stay informed about malware threats and to maintain up-to-date security software to protect against future infections. Regularly backing up important data and being cautious when downloading software or clicking on links can also help prevent malware infections. By understanding the risks and taking proactive measures, you can significantly reduce the likelihood of your computer being compromised by threats like Trojan.MSIL.Agent.VVF.
Analysis Report
General information
| Family Name: | Trojan.MSIL.Agent.VVF |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
1209962ff5b906e61e370dd4657527f2
SHA1:
f83067783396721fb50b6d764d4c228bed1a6d4d
SHA256:
C26806F9D67D651EFFD50D40F4F275AC27DEF9F1EE31AE1F8C289D3ED16FB150
File Size:
486.91 KB, 486912 bytes
|
|
MD5:
6dee6a8cc89a0a00a43db074535803d5
SHA1:
9582354ec1b77e62453d4ac68c0c686e25dd9e08
SHA256:
8983AC6BA515D20C49A2482C57500B02376A088E057B7B3F9F8E7618EAEB28E2
File Size:
2.41 MB, 2409472 bytes
|
|
MD5:
aeb91d5371bf9af7bf73bf4f6d98381f
SHA1:
f6dc981ed012428f5398096ea0dde72aeee4e349
SHA256:
24AA36005806B28E46E0D4DD434B80B011E0054B61DC67292B859CB5F7F05330
File Size:
3.55 MB, 3554304 bytes
|
|
MD5:
6b31d6f8e00d3b18c0c72aa186623cf8
SHA1:
ef3c2b332ea9668a95f59cfa7b89d7c8ae0d116d
SHA256:
4CEB8804D5998FEE1E9845250CA40754D616A68C1D0EED09C2239A48B2C642FE
File Size:
2.44 MB, 2439168 bytes
|
|
MD5:
c66793089feddb6184ac8c2b650ebcc0
SHA1:
fe4e3a12bb6e8c3e0ff419aa65c726f6466f28f4
SHA256:
4399E23D23135BCB6A2CAE35D3D212ED007EDA1FA27C363BFD62E0AA3D46D7B3
File Size:
4.66 MB, 4661248 bytes
|
Show More
|
MD5:
ca3c47dbe417494a0ef127f99cfbcd42
SHA1:
38ac4acee5044c4f2f3c06c01d0186a56eb633f3
SHA256:
4A677A34456D8A9A033252A3A77E7C36E25C1B9092333B357BFD016C3A31004B
File Size:
944.67 KB, 944672 bytes
|
|
MD5:
5b475937e8af9749c0c4b986573bd9f3
SHA1:
eacb43b68bc76552e8568aa30062a9194b12286a
SHA256:
05050FA330B593AC5E3B71E08EEE27A41E077B5686FFECDC517D063086D3C370
File Size:
1.83 MB, 1827328 bytes
|
|
MD5:
7dfd536f80ccbdda5428e0be995c7fb6
SHA1:
3ab35ff9c72e58e13d6336a4363fb631cfd76fd7
SHA256:
1B9D3D2169740E3C51BBC296883D3EBCA91B373C5C0FA861EAB36F1E5DBE9179
File Size:
3.77 MB, 3768352 bytes
|
|
MD5:
03a0f2ad16c7796058141d32c3154f38
SHA1:
33c4def2edb751f37eaa0c4026eba29c4876218f
SHA256:
4D81423A8E96E54566504946A6BFD500F47D0FC0D57C874AFD2CFD1B517AE34D
File Size:
3.69 MB, 3691008 bytes
|
|
MD5:
7cba34386c4a0802a7b8c945572e79b8
SHA1:
8f49b4cfacdf5903352aa9b9d9e6d96ba90b6168
SHA256:
3E1AE4D08610C49E2E43E1149A428846C7C98DA313C22772EE95B65AE20B9A55
File Size:
1.26 MB, 1259520 bytes
|
|
MD5:
2d832a62a14b3943b4236cd5137e29a4
SHA1:
9e39466267733bf9301d4bc35b1139ea5b8ba26f
SHA256:
4C80940B8A4AF46B4A8B1F55548D36F779420E41F02A4B374E0BA49AA9E3FA16
File Size:
701.95 KB, 701952 bytes
|
|
MD5:
d2ae7b970dec300098ac02e4b7ee05b4
SHA1:
1f2defd0ed25cfee37e65d79dfce6183d0901091
SHA256:
2F0C5AC3B8EE5DB0A87C48C3027ACA05AD5D7A4285B396D1B19CA558B35DAB35
File Size:
3.85 MB, 3854848 bytes
|
|
MD5:
c7394bf4a432b064a5f477d17de1e26c
SHA1:
69931294ed5bd10b93691716a22da7af25b018c4
SHA256:
00AFFC6D3CBEB15C2C1E5DC6AE704012F17B7F7CEC801A7FA39259D63551AC61
File Size:
5.06 MB, 5064224 bytes
|
|
MD5:
7a817e39a30a46c515965a2ae0e64e8c
SHA1:
3f8ebcf23d18e805a1ff6949e17c9ed0f9230abe
SHA256:
8B094BD1993F2BC690B5A7602DF90F3B662AEC307691AD865706B74D0760B02A
File Size:
3.71 MB, 3713024 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has TLS information
- File is .NET application
- File is 32-bit executable
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Comments | xiaomiauth.orh |
| Company Name |
|
| File Description |
Show More
|
| File Version |
|
| Internal Name |
Show More
|
| Legal Copyright |
|
| Original Filename |
Show More
|
| Product Name |
Show More
|
| Product Version |
|
File Traits
- .NET
- 00 section
- 2+ executable sections
- Agile.net
- dll
- Fody
- HighEntropy
- ntdll
- RijndaelManaged
- x64
Show More
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- MSIL.Agent.VVF
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| \device\namedpipe\dav rpc service | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| \device\namedpipe\pshost.134127142200690859.5076.defaultappdomain.powershell | Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288 |
| \device\namedpipe\wkssvc | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_dwl0olr5.yoi.psm1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_dx3ri4ny.0rx.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\autb79d.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\autb82a.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\guardian_src_1bdc4e57616d494f8c7746867f21b4b1.cs | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\guardian_src_466a61b761fc4e3a9df750a421b6183c.cs | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\guardian_src_5cebd16bb1b94be6ae5b0bbd98a25280.cs | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\guardian_src_e7ccc59cd6614f98a671b376dc3af842.cs | Generic Write,Read Attributes |
| c:\users\user\downloads\modified_scripts.ps1 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\modified_scripts.ps1 | Generic Write,Read Attributes |
| c:\users\user\downloads\modified_scripts.ps1 | Synchronize,Write Attributes |
| c:\users\user\downloads\mohamed_soft_kirin.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\users\user\downloads\mohamed_soft_kirin.exe | Generic Write,Read Attributes |
| c:\users\user\downloads\mohamed_soft_kirin.exe | Synchronize,Write Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ꉭ䮦仚ǜ | RegNtPreCreateKey |
| HKCU\software\xtrial::start | 潗㆜裞 | RegNtPreCreateKey |
| HKCU\software\xtrial::end | 꽗愳㵦裞 | RegNtPreCreateKey |
| HKCU\software\xtrial::days | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 싑掅ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | �E���� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | m�DT�� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �n �v��(�1`1�1HO @V� _�zk`{b��P� ������ ������m� Ù� ����$წ�� �=�SB1_ T�Vw���%������ �AE��D��&��$���L | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 䎰瞎㰁ǝ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| User Data Access |
|
| Other Suspicious |
|
| Anti Debug |
|
| Process Shell Execute |
|
| Syscall Use |
Show More
26 additional items are not displayed above. |
| Encryption Used |
|
| Network Winsock2 |
|
| Network Winsock |
|
| Process Manipulation Evasion |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Bcqllmnm\AppData\Local\Temp\f83067783396721fb50b6d764d4c228bed1a6d4d_0000486912.exe" "C:\Users\Bcqllmnm\AppData\Local\Temp\guardian_src_e7ccc59cd6614f98a671b376dc3af842.cs"
|
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Arfqkkxx\AppData\Local\Temp\f6dc981ed012428f5398096ea0dde72aeee4e349_0003554304.exe" "C:\Users\Arfqkkxx\AppData\Local\Temp\guardian_src_466a61b761fc4e3a9df750a421b6183c.cs"
|
powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File "c:\Users\user\downloads\Modified_Scripts.ps1"
|
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Npvydebq\AppData\Local\Temp\3ab35ff9c72e58e13d6336a4363fb631cfd76fd7_0003768352.exe" "C:\Users\Npvydebq\AppData\Local\Temp\guardian_src_5cebd16bb1b94be6ae5b0bbd98a25280.cs"
|
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Yhvduayc\AppData\Local\Temp\3f8ebcf23d18e805a1ff6949e17c9ed0f9230abe_0003713024.exe" "C:\Users\Yhvduayc\AppData\Local\Temp\guardian_src_1bdc4e57616d494f8c7746867f21b4b1.cs"
|