Malware

How to remove “Mal/ILAgent-B”?

Malware Removal

The Mal/ILAgent-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/ILAgent-B virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Mal/ILAgent-B?


File Info:

name: EF2B8152FF8B1ABAA977.mlw
path: /opt/CAPEv2/storage/binaries/95aee869076b042ee22f70b0a1fd9c1d968db88400042b971bdee82226d3fa9c
crc32: 8E49EDAF
md5: ef2b8152ff8b1abaa9772db14084e146
sha1: df018e192e96b4e78fe363bad14870c0609b31bc
sha256: 95aee869076b042ee22f70b0a1fd9c1d968db88400042b971bdee82226d3fa9c
sha512: a4ab1a7f781c52821076d42af93646e4a837d99dde63e36374dda554b81206c780e83a3a80b51b17e1648d55ccc883bb4507c3be712725dc50b1d96021376e76
ssdeep: 1536:LhAW2VCVDTb9pZZet4gsbNikAX0bIe7poIE4d3:1JgC1VZ7gwNWEbIe7poIhx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1630C9C765472DFC86BC972CEA82C64EA60747B530BD207A05312ED9A0D99BCF191F3
sha3_384: 08177670a23e4feadab9b3f3115fe8bb47c644040eeff8f9d81bdeec3a462244d96eb3149c8ea04013fc494f5b4f089b
ep_bytes: ff250020400000000000000000000000
timestamp: 2096-08-03 01:58:05

Version Info:

Translation: 0x0000 0x04b0
Comments: Programs Engine
CompanyName: Microsoft® Windows®
FileDescription: Programs Engine
FileVersion: 10.0.19041.746
InternalName: Task24Main.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Task24Main.exe
ProductName: Programs Engine
ProductVersion: 10.0.19041.746
Assembly Version: 10.0.19041.746

Mal/ILAgent-B also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.148164
FireEyeGeneric.mg.ef2b8152ff8b1aba
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Lazy.148164
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058f7721 )
K7GWTrojan ( 0058f7721 )
BitDefenderThetaGen:NN.ZemsilCO.34582.em0@aGnkh@
CyrenW32/MSIL_Kryptik.GWD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.VFA
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Lazy.148164
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Lazy.148164
EmsisoftGen:Variant.Lazy.148164 (B)
F-SecureHeuristic.HEUR/AGEN.1203561
VIPREGen:Variant.Lazy.148164
McAfee-GW-EditionPWS-FDLQ!EF2B8152FF8B
SophosMal/ILAgent-B
GDataGen:Variant.Lazy.148164
WebrootW32.Trojan.Dropper
AviraHEUR/AGEN.1203561
MAXmalware (ai score=81)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Lazy.D242C4
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5072241
McAfeePWS-FDLQ!EF2B8152FF8B
MalwarebytesTrojan.Crypt.MSIL
APEXMalicious
RisingTrojan.Agent!8.B1E (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.VFA!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.92e96b

How to remove Mal/ILAgent-B?

Mal/ILAgent-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment