Backdoor

What is “Dropped:Backdoor.MSIL.Agent.GD”?

Malware Removal

The Dropped:Backdoor.MSIL.Agent.GD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Backdoor.MSIL.Agent.GD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
gop5top.ddns.net

How to determine Dropped:Backdoor.MSIL.Agent.GD?


File Info:

crc32: 4B2098DB
md5: ddefb41684da20ba5c25a47ae0299a64
name: DDEFB41684DA20BA5C25A47AE0299A64.mlw
sha1: 5fa1efdcc0e7de7cabfab487cee4d8b8917fd42d
sha256: c2cad09e6d6f7fc18b707d6ebac33f62e48812b11d9304a8776bf3047e631b96
sha512: 6d704fb2f35269044e5a0300bb44a0ca6a32c361d15e988dbfb02f720f292a68e99c9c4a4434f74d06ba9715921d735e6c332e60a65b8a2d24e4f77bcf0909a3
ssdeep: 6144:eKPEmYsFRSONQwCdSSrALwIYsYdb7nytJR6k5YoDijziaW5:fpYsFgONQwCcSwzPR5DD0eaS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Dropped:Backdoor.MSIL.Agent.GD also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Backdoor.MSIL.Agent.GD
FireEyeGeneric.mg.ddefb41684da20ba
CAT-QuickHealTrojanDropper.Small.PQ4
McAfeeGenericRXGS-GO!DDEFB41684DA
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00515e9f1 )
BitDefenderDropped:Backdoor.MSIL.Agent.GD
K7GWTrojan ( 00515e9f1 )
Cybereasonmalicious.684da2
InvinceaMal/Generic-S
CyrenW32/GenTroj.S.gen!Eldorado
SymantecTrojan.Nancrat
APEXMalicious
AvastWin32:GenMalicious-NUS [Trj]
KasperskyBackdoor.Win32.Poison.ggrf
NANO-AntivirusTrojan.Win32.Poison.cbeljp
ViRobotBackdoor.Win32.Agent.67584.L
TencentMalware.Win32.Gencirc.10b3e7f9
Ad-AwareDropped:Backdoor.MSIL.Agent.GD
SophosMal/Generic-S
DrWebTrojan.MulDrop8.22787
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
EmsisoftDropped:Backdoor.MSIL.Agent.GD (B)
IkarusVirus.Win32.Vbinder
JiangminBackdoor/Poison.abtg
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
MicrosoftVirTool:Win32/CeeInject.WI!bit
ArcabitBackdoor.MSIL.Agent.GD
ZoneAlarmBackdoor.Win32.Poison.ggrf
GDataWin32.Trojan-Dropper.Agent.AMY
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fynloski.R43608
Acronissuspicious
BitDefenderThetaAI:Packer.7D3E25E91F
ALYacDropped:Backdoor.MSIL.Agent.GD
VBA32BScope.Backdoor.Poison
MalwarebytesBackdoor.Dropper
PandaTrj/Injector.BH
ESET-NOD32a variant of Win32/TrojanDropper.Small.NMM
RisingDropper.Win32.Small.bnv (CLASSIC)
YandexTrojan.GenAsa!T8P/UkYT/k8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Xorist.ET!tr
WebrootW32.Dropper.Gen
AVGWin32:GenMalicious-NUS [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.3FBB.Malware.Gen

How to remove Dropped:Backdoor.MSIL.Agent.GD?

Dropped:Backdoor.MSIL.Agent.GD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment