Backdoor

About “Backdoor.MSIL.Agent.qef” infection

Malware Removal

The Backdoor.MSIL.Agent.qef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Agent.qef virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.MSIL.Agent.qef?


File Info:

crc32: B3C3569A
md5: c6c5404003dc530af7469d26b70effae
name: C6C5404003DC530AF7469D26B70EFFAE.mlw
sha1: cd462ffa5b9cc196efcc6a3b7ea84620c163afd1
sha256: dff16ce17a870d80d120c36ebbeab819071c9b57bd9568fbdb4ecb2958a64486
sha512: e5992211709b296e8aba12bba4d142d26e7d6633f582be84578fdb5cf5a28754813f53026719b36fae965b8ccf7850746b6b13603ca622aba68c02f09df831d4
ssdeep: 768:u6u75oa4fu124AqFjXeJBKh0p29SgR63T:C75CPkj8KhG29jsT
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Backdoor.MSIL.Agent.qef also known as:

K7AntiVirusTrojan ( 003ca8581 )
LionicTrojan.Win32.Generic.lMGJ
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.3459
ClamAVWin.Packed.Bladabindi-7086597-0
CAT-QuickHealTrojan.Bladabindi.B3
McAfeeTrojan-FIGN
CylanceUnsafe
ZillyaTrojan.Bladabindi.Win32.14961
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Bladabindi.9302522b
K7GWTrojan ( 003ca8581 )
Cybereasonmalicious.003dc5
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Bladabindi.A.gen!Eldorado
SymantecBackdoor.Ratenjay
ESET-NOD32MSIL/Bladabindi.F
APEXMalicious
AvastMSIL:Agent-BXF [Trj]
CynetMalicious (score: 100)
KasperskyBackdoor.MSIL.Agent.qef
BitDefenderIL:Trojan.MSILZilla.6820
NANO-AntivirusTrojan.Win32.Dwn.dbxzfj
ViRobotBackdoor.Win32.Bladabindi.Gen.A
MicroWorld-eScanIL:Trojan.MSILZilla.6820
TencentMsil.Backdoor.Agent.Taev
Ad-AwareIL:Trojan.MSILZilla.6820
SophosMal/Generic-R + Troj/MSIL-HX
ComodoTrojWare.MSIL.Bladabindi.KX@52g0y5
BitDefenderThetaGen:NN.ZemsilF.34236.bmW@aOZwcUh
VIPRETrojan.MSIL.Bladabindi.agxy (v)
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.BackdoorNJRat.mm
FireEyeGeneric.mg.c6c5404003dc530a
EmsisoftIL:Trojan.MSILZilla.6820 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Autoit.dce
WebrootW32.Backdoor.Bladabindi
AviraTR/ATRAPS.Gen
eGambitRAT.njRat
Antiy-AVLTrojan/Generic.ASBOL.A8F4
KingsoftHeur.SSC.9159.1216.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.AJ
SUPERAntiSpywareTrojan.Agent/Gen-Barys
GDataMSIL.Backdoor.Bladabindi.AV
AhnLab-V3Trojan/Win32.Bladabindi.C202658
Acronissuspicious
VBA32Trojan.MSIL.Disfa
MAXmalware (ai score=81)
MalwarebytesBackdoor.Bladabindi.MSIL
PandaGeneric Malware
TrendMicro-HouseCallBKDR_BLADABI.SMC
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexTrojanSpy.Agent!KaVS6Oys66c
IkarusTrojan.Msil
MaxSecureTrojan.MSIL.Agent.Rzr
FortinetMSIL/Agent.PPV!tr
AVGMSIL:Agent-BXF [Trj]
Paloaltogeneric.ml

How to remove Backdoor.MSIL.Agent.qef?

Backdoor.MSIL.Agent.qef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment