Backdoor

Backdoor.Agent.MSC removal tips

Malware Removal

The Backdoor.Agent.MSC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.MSC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Backdoor.Agent.MSC?


File Info:

name: 185DDCB4CBA27B72D4D8.mlw
path: /opt/CAPEv2/storage/binaries/a53eadddba402a8d70ac12c3d05b761a3247b1b82fe78f0a8d8d0656a7ba1b8a
crc32: CFC06EE2
md5: 185ddcb4cba27b72d4d8be4784cc5797
sha1: 19ed1e2a99acb28baf0eb13b98ef7c11b65ca4e1
sha256: a53eadddba402a8d70ac12c3d05b761a3247b1b82fe78f0a8d8d0656a7ba1b8a
sha512: d6b65d5959f9d4e42d6cbfdf7d2bd0f1e84459c4f7f6475621652cc6cb4bb71ff307b45a8b9dba514e90f7d7bf5d4b22c021bfd1966c110ae830b3286a328be5
ssdeep: 6144:blT5T69oUxIoBjf0bm/J6aa7U7FeI3ABcHI7fSgwVs8ea:blT5ixIoBjMy/J6l2vwBcHyfw4a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14354F116E398ADB1D9190632CD2E582003BEEE5599F1861F59CD713EAAB33C35187C8F
sha3_384: 9d83cf28f24fb4b0d51a63ddc71bc7949055ad834f8eb8875607b9057f076ce072de3dca11cce53c8bfb9c8b250af037
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-04-27 20:12:13

Version Info:

Translation: 0x0000 0x04b0
Comments: VAIO Care
CompanyName: Sony Corporation
FileDescription: VCREAD
FileVersion: 8.2.0.14260
InternalName: VCREAD.exe
LegalCopyright: ©2011, 2012, 2013 Sony Corporation
OriginalFilename: VCREAD.exe
ProductName: VCREAD
ProductVersion: 8.2.0.14260
Assembly Version: 8.2.0.14260

Backdoor.Agent.MSC also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Benin.5
FireEyeGeneric.mg.185ddcb4cba27b72
McAfeeGeneric-FAVD!185DDCB4CBA2
MalwarebytesBackdoor.Agent.MSC
ZillyaTrojan.Inject.Win32.74040
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e39a1 )
AlibabaTrojan:MSIL/Injector.d24fd5ef
K7GWTrojan ( 0055e39a1 )
Cybereasonmalicious.4cba27
ArcabitTrojan.MSIL.Benin.5
BitDefenderThetaGen:NN.ZemsilF.34084.rm0@augzhKp
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.DMO
TrendMicro-HouseCallTROJ_GEN.R002C0PJV21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.MSIL.Benin.5
NANO-AntivirusTrojan.Win32.Inject.dbqyph
AvastMSIL:Zbot-AE [Trj]
TencentWin32.Trojan.Generic.Dxxd
Ad-AwareGen:Heur.MSIL.Benin.5
EmsisoftGen:Heur.MSIL.Benin.5 (B)
ComodoMalware@#1czd8wkgx8oyk
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PJV21
McAfee-GW-EditionGeneric-FAVD!185DDCB4CBA2
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
JiangminTrojan.Generic.espql
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1117403
Antiy-AVLTrojan/Win32.Inject
KingsoftWin32.Troj.Inject.mt.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
GDataGen:Heur.MSIL.Benin.5
CynetMalicious (score: 100)
VBA32Trojan.Inject
ALYacGen:Heur.MSIL.Benin.5
APEXMalicious
YandexTrojan.Inject!KSyk+JhmD0A
MAXmalware (ai score=86)
eGambitUnsafe.AI_Score_100%
FortinetW32/Inject.DMO!tr
WebrootTrojan.Dropper.Gen
AVGMSIL:Zbot-AE [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Backdoor.Agent.MSC?

Backdoor.Agent.MSC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment