Malware

About “MSIL/Agent.BON” infection

Malware Removal

The MSIL/Agent.BON is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.BON virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/Agent.BON?


File Info:

crc32: 98B92C04
md5: c1a81c1049f136d6167a6f542543e289
name: 2.exe
sha1: ba9507eaa6aa7123e94b1c8d51180729235e622a
sha256: f2ffb93ca9c033204658198575c1ce2ba1dfa55641a1fb0b74f8caf21432a47b
sha512: b664a288b930120e5c52e34950c345c5f346fdc2df999bd0918e9c4a6d5a21b808a0b25580c4339991171525d3ec7d5dbb0750705b0896ae194a21ec58d05b5d
ssdeep: 768:cWDUU+uRiWuKH76fq4zkW6vcMcQ+C/1WKSozO5zCwJqLyLQuBpNe2GY40Rs:BR5RrL6y0McQ+S1W6O5KLle+2GY40S
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MSIL/Agent.BON also known as:

MicroWorld-eScanTrojan.GenericKD.33043890
FireEyeGeneric.mg.c1a81c1049f136d6
McAfeeArtemis!C1A81C1049F1
CylanceUnsafe
AegisLabTrojan.Win32.Emotet.L!c
SangforMalware
K7AntiVirusTrojan ( 0053a3201 )
BitDefenderTrojan.GenericKD.33043890
Cybereasonmalicious.aa6aa7
Invinceaheuristic
SymantecRansom.Cerber
APEXMalicious
GDataTrojan.GenericKD.33043890
KasperskyTrojan-Banker.Win32.Emotet.expj
AlibabaTrojan:Win32/Emotet.a0a01130
RisingTrojan.Agent!8.B1E (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33043890 (B)
McAfee-GW-EditionBehavesLike.Win32.Vundo.kc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
AviraTR/Agent.mmwsz
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Bluteal!rfn
ArcabitTrojan.Generic.D1F835B2
ZoneAlarmTrojan-Banker.Win32.Emotet.expj
Acronissuspicious
VBA32BScope.Backdoor.Tofsee
Ad-AwareTrojan.GenericKD.33043890
MalwarebytesTrojan.MalPack.VAK
ESET-NOD32MSIL/Agent.BON
TrendMicro-HouseCallTROJ_GEN.R015H0DB520
TencentWin32.Trojan-banker.Emotet.Sxoa
SentinelOneDFI – Malicious PE
FortinetPossibleThreat.MU
BitDefenderThetaGen:NN.ZexaF.34084.euW@a82yoBp
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.1e8

How to remove MSIL/Agent.BON?

MSIL/Agent.BON removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment