Malware

About “DDoSTool.Agent.MSIL” infection

Malware Removal

The DDoSTool.Agent.MSIL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DDoSTool.Agent.MSIL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

How to determine DDoSTool.Agent.MSIL?


File Info:

crc32: 186503B9
md5: 2fcf2d4084357ed5c513a7128862902b
name: soar.exe
sha1: 3dbb835f010f78f66ef8202e72b8122a0abe34ab
sha256: bbaf9d13cd518921eed1b19128e927a471b2bc2a76a58d64e665530747208120
sha512: 53b335218f38a9a4056f077c0c26a1b33a88c1f66325d04ef40bb8c72da4134dafdee26fc0d83c6d12143cf8313e65508ed4c5ed261764e3509892333607bd54
ssdeep: 3072:dtqt5M3X8vDaSTaPGxNvF8JH1b0/1Y+oez:dd3X87aSGex0JVbI1Y+oe
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.0
InternalName: X.exe
FileVersion: 1.0.0.0
ProductName: X
ProductVersion: 1.0.0.0
FileDescription: X
OriginalFilename: X.exe
Translation: 0x0000 0x04b0

DDoSTool.Agent.MSIL also known as:

MicroWorld-eScanGen:Variant.Razy.453331
FireEyeGeneric.mg.2fcf2d4084357ed5
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeRDN/Generic.fvf
ALYacGen:Variant.Razy.453331
CylanceUnsafe
ZillyaTool.Agent.Win32.30705
SangforMalware
K7AntiVirusTrojan ( 00544b991 )
BitDefenderGen:Variant.Razy.453331
K7GWTrojan ( 00544b991 )
Cybereasonmalicious.084357
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Razy.453331
KasperskyHEUR:Trojan-DDoS.MSIL.Dictator.gen
AlibabaTrojan:MSIL/Dictator.3778c4d3
NANO-AntivirusTrojan.Win32.Razy.fzhqcf
AegisLabTrojan.MSIL.Dictator.9!c
RisingTrojan.DDos-Dictator!8.1084E (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.453331 (B)
F-SecureHeuristic.HEUR/AGEN.1039855
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.MSIL.Flooder
CyrenW32/Trojan.FGUI-7898
JiangminTrojanDDoS.MSIL.ax
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1039855
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=100)
ArcabitTrojan.Razy.D6EAD3
ZoneAlarmHEUR:Trojan-DDoS.MSIL.Dictator.gen
MicrosoftTrojan:Win32/Skeeyah.A!MTB
AhnLab-V3Trojan/Win32.RemoteAccess.R289289
Acronissuspicious
Ad-AwareGen:Variant.Razy.453331
MalwarebytesDDoSTool.Agent.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Agent.CJQ
TencentMsil.Trojan-ddos.Dictator.Hwdr
YandexFlooder.Agent!eAysKgTUSLo
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.74146878.susgen
FortinetMSIL/Agent.DM!tr
BitDefenderThetaGen:NN.ZemsilF.34090.lm0@a8B!sln
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.DDoS.aa1

How to remove DDoSTool.Agent.MSIL?

DDoSTool.Agent.MSIL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment