Threat Database Trojans Trojan.MSIL.Downloader.Agent.IU

Trojan.MSIL.Downloader.Agent.IU

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 323
First Seen: June 28, 2022
Last Seen: August 3, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.Agent.IU on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and potentially lead to further malicious activities. It is essential to understand the nature of this threat and take appropriate steps to remove it and protect your system.

What Is Trojan.MSIL.Downloader.Agent.IU?

Trojan.MSIL.Downloader.Agent.IU is a type of Trojan horse malware that can download and install additional malicious components on your system. The name suggests that it is written in MSIL (Microsoft Intermediate Language), which is a platform-independent intermediate representation of the .NET Framework. This type of malware can be particularly dangerous as it can evolve and change its behavior over time, making it challenging to detect and remove.

How Trojan.MSIL.Downloader.Agent.IU Operates

Trojan.MSIL.Downloader.Agent.IU typically operates by exploiting vulnerabilities in your system or tricking you into installing it. Once installed, it can connect to a command and control server to receive instructions and download additional malware components. This can lead to a range of malicious activities, including data theft, ransomware attacks, or the installation of other types of malware. The malware can also modify system settings and disable security software to avoid detection.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Downloader.Agent.IU infection can vary, but common signs include slow system performance, unexpected pop-ups or ads, and unfamiliar programs or icons on your desktop. You may also notice that your system is crashing or freezing frequently, or that your internet connection is slow or unstable. In some cases, you may not notice any symptoms at all, which is why regular system scans and monitoring are essential for detecting and removing malware.

How to Remove Trojan.MSIL.Downloader.Agent.IU

  1. Restart your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full system scan to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full system scan to ensure that all instances of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Downloader.Agent.IU from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and taking proactive measures to protect your system, you can minimize the risk of infection and prevent further malicious activities. Remember to always keep your operating system and security software up to date, and to be cautious when downloading and installing software from the internet. Regular system scans and monitoring can help detect and remove malware before it causes significant damage.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.Agent.IU
Signature status: Self Signed

Known Samples

MD5: ed95959996160b58777179a79897b14c
SHA1: cf530e913572d2f7e91f17f180909f66f23626ba
SHA256: 689ED34C6427DD409759C5C05765FB1C3206BA82CD08639B527CE09F16C08A83
File Size: 3.02 MB, 3017696 bytes
MD5: c6857e0a4d4e40145313521e395a322e
SHA1: a286bc8f5065185efb39b4e4a44629a544d123c0
SHA256: F242A989DFB0E19BDE00207A18B2606CA4AA50EECA3EB7A798DEE809A2D322A7
File Size: 2.74 MB, 2742752 bytes
MD5: f5ef390b99ea351538c81c012187feaa
SHA1: f00e682face540099d5df4d030b4ff849487e1af
SHA256: E8E7F4B4D2DEC9642EDA6BCAAA6FF89CA64DDC3A40746CA139CCE9A6D6E4EBD3
File Size: 3.72 MB, 3716808 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.0.0.0
  • 1.3.0.0
  • 1.1.0.0
Comments
  • iCloud Bypass A5 Device One Click (No Arduino)
  • iCloud Bypass AIO+
Company Name
  • GSM ADJAA COMPANY
  • Skynet
File Description
  • rKeyTools Premium
  • Skynet A5 Tool
File Version
  • 2.0.0.0
  • 1.3.0.0
  • 1.1.0.0
Internal Name
  • rKeyTools Premium.exe
  • skynetA5.exe
Legal Copyright
  • Copyright © 2025
  • Copyright © GSM ADJAA COMPANY 2022 - 2026
Legal Trademarks
  • GSM ADJAA COMPANY
  • Skynet
Original Filename
  • rKeyTools Premium.exe
  • skynetA5.exe
Product Name
  • iCloud Bypass AIO+
  • skynetA5
Product Version
  • 2.0.0.0
  • 1.3.0.0
  • 1.1.0.0

Digital Signatures

Signer Root Status
RKEYTOOLS RKEYTOOLS Self Signed
skynet-tool.com skynet-tool.com Self Signed

File Traits

  • .NET
  • HighEntropy
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 990
Potentially Malicious Blocks: 170
Whitelisted Blocks: 573
Unknown Blocks: 247

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x 0 0 x x x 0 x x x x x x 0 x x x x x x x ? x x x x 0 x x x x x x x x x 0 x x x x x 0 ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 x ? 0 0 0 0 ? ? 0 ? 0 ? ? 0 ? ? 0 0 ? 0 0 x ? ? ? x 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? x 0 0 0 0 0 ? ? ? 0 0 0 ? ? 0 0 0 ? 0 x ? ? ? ? 0 ? ? 0 0 0 ? 0 0 ? ? ? ? ? 0 0 0 ? ? 0 0 0 0 ? 0 ? ? ? ? 0 ? ? 0 0 0 ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? 0 0 ? ? ? 0 0 ? 0 ? ? ? ? ? ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x ? 0 0 ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x ? ? ? ? ? ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? 0 0 0 0 0 ? 0 ? ? ? 0 0 0 ? 0 ? ? ? ? x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 ? ? ? ? ? ? ? x ? x ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 x ? 0 0 0 0 ? ? ? 0 0 ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 ? x 0 ? ? 0 0 0 0 0 0 0 0 x ? 0 0 0 ? x ? ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? x 0 ? 0 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 ? ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? 0 0 0 x ? 0 0 0 0 0 0 0 x ? 0 0 0 0 x ? 0 0 0 0 x ? 0 0 0 0 x ? 0 0 0 0 0 x 0 0 0 x ? 0 0 x ? 0 0 x ? 0 0 x ? 0 0 x ? x ? 0 0 0 0 0 x ? 0 0 0 0 0 0 x ? 0 0 0 0 0 x ? 0 0 0 x ? 0 0 0 0 x ? 0 0 0 0 x ? 0 0 0 0 ? 0 0 0 x x 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 ? x ? x ? x x ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • CheckRemoteDebuggerPresent
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Encryption Used
  • BCryptOpenAlgorithmProvider