Backdoor

About “Backdoor.Agent.MSIL” infection

Malware Removal

The Backdoor.Agent.MSIL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.MSIL virus can do?

  • Network activity detected but not expressed in API logs

How to determine Backdoor.Agent.MSIL?


File Info:

crc32: BB585B8A
md5: 4a43ebacc19f8c4b221404de598c1c4a
name: aspnet.exe
sha1: 9f8e9450719c1c9f8fce6c453c5d2eeb8822e10b
sha256: cb032ef851a9eb44a2f2bcf5f21c7aa7020bc2b38560ecf10194ebfb6991a2c3
sha512: 5e7dfa976ddf109ea81acc6a54091bbe66948cf0b2e803ad111b64e668c0c51bd532902037466cdd201b37f1fccdf4a1d402382bbb11d58de4a30f1dc5492702
ssdeep: 3072:/DUZZZZZOAwwwwwwwgdWmyGINKKAKFAJoXGD0XMMdhXHiRgfYH:XmyGITehD0XTXPfa
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: aspnet_regsql.exe
FileVersion: 4.8.3761.0 built by: NET48REL1
CompanyName: Microsoft Corporation
PrivateBuild: DDBLD438
Comments: Flavor=Retail
ProductName: Microsoftxae .NET Framework
ProductVersion: 4.8.3761.0
FileDescription: aspnet_regsql.exe
OriginalFilename: aspnet_regsql.exe
Translation: 0x0409 0x04b0

Backdoor.Agent.MSIL also known as:

MicroWorld-eScanTrojan.GenericKD.33658740
FireEyeTrojan.GenericKD.33658740
McAfeeArtemis!4A43EBACC19F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005587dc1 )
BitDefenderTrojan.GenericKD.33658740
K7GWTrojan ( 005587dc1 )
ArcabitTrojan.Generic.D2019774
TrendMicroTROJ_GEN.R011C0WE820
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.MSIL.Agent.gen
AlibabaTrojan:MSIL/gowqc.8177b318
TencentMsil.Trojan.Agent.Pdcl
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33658740 (B)
F-SecureTrojan.TR/Agent.gowqc
DrWebTrojan.DownLoader33.31334
ZillyaTrojan.Agent.Win32.1320038
FortinetMSIL/Ursu.7C89!tr
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
CyrenW32/Trojan.KZLO-7975
JiangminTrojan.MSIL.ommi
AviraTR/Agent.gowqc
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Dynamer!rfn
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
ALYacTrojan.GenericKD.33658740
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Agent.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Agent.BLR
TrendMicro-HouseCallTROJ_GEN.R011C0WE820
RisingTrojan.Agent!8.B1E (CLOUD)
MaxSecureTrojan.Malware.8703358.susgen
GDataWin32.Trojan.InfoStealer.A
Ad-AwareTrojan.GenericKD.33658740
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM03.0.8667.Malware.Gen

How to remove Backdoor.Agent.MSIL?

Backdoor.Agent.MSIL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment