Threat Database Trojans Trojan.MSIL.HackAgent.E

Trojan.MSIL.HackAgent.E

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,571
Threat Level: 80 % (High)
Infected Computers: 4,930
First Seen: October 6, 2021
Last Seen: June 24, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.HackAgent.E on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.MSIL.HackAgent.E?

Trojan.MSIL.HackAgent.E is a type of malware that can infect your computer without your knowledge or consent. The name suggests that it is a Trojan, which is a broad category of malware that can include various types of threats, such as viruses, worms, and spyware. The fact that it is detected as Trojan.MSIL.HackAgent.E indicates that it has been identified as a potential threat by your security software.

How Trojan.MSIL.HackAgent.E Operates

Trojan-type threats like Trojan.MSIL.HackAgent.E typically operate by exploiting vulnerabilities in your system or tricking you into installing them. They can be disguised as legitimate software or attached to seemingly harmless files. Once installed, they can run in the background, collecting sensitive information, stealing passwords, or taking control of your system. They can also download additional malware, creating a more significant threat to your security.

Symptoms of Infection

The symptoms of a Trojan.MSIL.HackAgent.E infection can vary, but common signs include slow system performance, unexpected pop-ups, and unfamiliar programs or icons on your desktop. You may also notice that your browser is being redirected to unfamiliar websites or that your search results are being hijacked. In some cases, you may not notice any symptoms at all, which is why regular scans with a reputable security tool are essential.

How to Remove Trojan.MSIL.HackAgent.E

  1. Restart your computer in Safe Mode with Networking to prevent the malware from loading and to give you a clean environment to work in.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware. Make sure your security software is up-to-date to ensure the best possible detection and removal.
  3. Uninstall any suspicious programs that you have installed recently, as they may be related to the malware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that the malware may have installed.
  5. Reboot your computer and run another scan with your security software to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.HackAgent.E from your system requires careful attention to detail and a thorough understanding of the threat. By following the steps outlined above, you can help ensure that your system is clean and secure. Remember to always be cautious when installing new software, and never open attachments or click on links from unfamiliar sources. Regular scans with a reputable security tool can help detect and prevent future infections, keeping your system and personal data safe.

Analysis Report

General information

Family Name: Trojan.MSIL.HackAgent.E
Signature status: No Signature

Known Samples

MD5: 6ebee70fcc3b120b42d841dd44b851f9
SHA1: 9a69ac02dc76b36436165d26eac74fe8843596cf
SHA256: 17B6EE5A676955AFA8185D749FA8DA535355DB40C87CD50145A3CA257F81F078
File Size: 725.52 KB, 725520 bytes
MD5: 9530ce73891116cd5070185ea085de30
SHA1: eafcc7650239921050c87bb120b9cee6d18e1ed5
SHA256: C5D35B9FA8D38BA26A553AF71682499494EDEE1BFF13E5533E0E66424D2AE8D8
File Size: 1.01 MB, 1014800 bytes
MD5: 860b143a3672a628cf49a9a55ba74650
SHA1: 88ceb8218accc4af38b4f35c3c4cd43b7b498944
SHA256: 01E726FDB313B9EC2B15B281E8005325010586EC021981D8332C34B3E781F7E0
File Size: 5.73 MB, 5729808 bytes
MD5: 8251678ed82bbfe4667e15c0f39f841a
SHA1: 0e66f1b18cdc31501476fb0b5fca962007d23c8d
SHA256: E8076B5807090431C3E63EAFE2DB5C8FA7377D410A2DA5CF409BB7439CD4F6AD
File Size: 1.93 MB, 1934352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.0.3.0
  • 1.0.0.0
Comments External iPad Plist
Company Name External iPad Plist
File Description
  • External iPad Plist
  • lofyfree
  • LU Team - Fake Reset Utility
  • LU_A5_no_aurdino
File Version
  • 1.0.3.0
  • 1.0.0.0
Internal Name
  • External iPad Plist.exe
  • lofyfree.exe
  • LU Team - Fake Reset Utility.exe
  • LU_A5_no_aurdino.exe
Legal Copyright
  • Copyright © 2025
  • Copyright © 2026
Legal Trademarks External iPad Plist
Original Filename
  • External iPad Plist.exe
  • lofyfree.exe
  • LU Team - Fake Reset Utility.exe
  • LU_A5_no_aurdino.exe
Product Name
  • External iPad Plist
  • lofyfree
  • LU Team - Fake Reset Utility
  • LU_A5_no_aurdino
Product Version
  • 1.0.3.0
  • 1.0.0.0

File Traits

  • .NET
  • Agile.net
  • Fody
  • HighEntropy
  • ntdll
  • RijndaelManaged
  • WriteProcessMemory
  • x64
  • x86

Block Information

Total Blocks: 692
Potentially Malicious Blocks: 154
Whitelisted Blocks: 173
Unknown Blocks: 365

Visual Map

x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x x 0 0 0 0 ? ? ? ? ? ? x ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x x 0 x x 0 0 x x x x x x x x x x x x 0 x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x 0 0 x 0 0 0 0 x x x x x x x x x x x x x x x x x x x 0 x 0 0 x x x x 0 0 x x x 0 x x x x 0 0 x 0 x x x x x x x x x x x x 0 x x 0 0 x x 0 0 0 0 x x x x x x x x x x x 0 x x x x x x x x x 0 x x x x x 0 0 ? x x x 0 0 0 x x x 0 x x 0 0 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.HackAgent.E

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Encryption Used
  • BCryptOpenAlgorithmProvider
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...