Jump to content

Nazwa wykrycia: MSIL/Agent.XCL


Go to solution Solved by Marcos,

Recommended Posts

Win Server 2012

NEW NOTIFICATION
Detection type: Trojan 
Detection name: MSIL/Agent.XCL 
Computer name: ASCS-SV-01-T110 
Logged in user: ASCS-SV-01-T110\Agnieszka 
Speech time: 19/09/2024, 14:58:58 CEST 
Scanner: Real-time file system protection 
Action taken: Cured by deletion
Detection type: Trojan
Detection name: MSIL/Agent.XCL
Computer name: ASCS SV 01 T110
Logged in user: ASCS SV 01 T110\Agnieszka
Speech time: 19/09/2024, 14:58:58 CEST
Scanner: Real-time file system protection
Action taken: Cured by deletion

after last update, it is when we encrypt using this tool: PDFKey Pro | Unlock PDF files right now

Please note, this tool is being used for 4 years, there were never had problems. Now there is no problem using it on PCs. Problem is only on server

Every time we try to encrypt any pdf file on server, we receive notification. On PC, when we encrypt even the same pdf file, everything is ok, no notification

Note on server 2012 we have current ESET ver installed

 

 

Screenshot 2024-09-19 15-19-21.jpg

Edited by root
Link to comment
Share on other sites

I downloaded the installer and submitted it to CrowdStrike Falcon sandbox. The scan resulted in a malicious behavior detection: https://www.hybrid-analysis.com/sample/1097b94c48cedd27ccabcab2ea5f84f2b9740c0aafc9f6568dd74027c8a41664/66ec3354f573c272c2000a61 .

Edited by itman
Link to comment
Share on other sites

  • Administrators
  • Solution

We've removed the detection. The file appears to be clean and is not subject to detection.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...