Malware

MSIL/Agent.DEB (file analysis)

Malware Removal

The MSIL/Agent.DEB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.DEB virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Agent.DEB?


File Info:

crc32: E67251C2
md5: eb427ae63abfe2288f7edfdec1ee86ff
name: EB427AE63ABFE2288F7EDFDEC1EE86FF.mlw
sha1: 5686fa118a3c2a1b3e353c8884fae5a6f22ce212
sha256: 047ad5c77d1afe5a4e2e21ea10dd79e0a4d939f74e373b447f1096ec0cf18917
sha512: 4c69a5fae46d00e2de0d06aa9635bcef51276ec17b87e534e62104983986c14137644a4e351cbdb38624959959583c61cc573a93940626bd9202423832b2fb53
ssdeep: 384:mC701Q1jLSvBRswt8+SUZuohH0AIDFbpq+2Vk50E3vfXNkfSnN:LyBRswt8+SUZ/H+FbQYXNh
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: services.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: services
ProductVersion: 1.0.0.0
FileDescription: services
OriginalFilename: services.exe

MSIL/Agent.DEB also known as:

MicroWorld-eScanTrojan.GenericKD.45019198
CAT-QuickHealBackdoor.MSIL
McAfeeRDN/Generic BackDoor
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Bladabindi.m!c
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.GenericKD.45019198
K7GWTrojan ( 00574c821 )
K7AntiVirusTrojan ( 00574c821 )
ArcabitTrojan.Generic.D2AEF03E
CyrenW32/Trojan.DSTL-6989
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
AlibabaBackdoor:MSIL/Bladabindi.d5da8429
Ad-AwareTrojan.GenericKD.45019198
SophosMal/Generic-S
ComodoMalware@#2yk3vxwy4eugp
F-SecureTrojan.TR/Agent.mskuk
TrendMicroTROJ_GEN.R06BC0PLJ20
McAfee-GW-EditionRDN/Generic BackDoor
FireEyeGeneric.mg.eb427ae63abfe228
EmsisoftTrojan.GenericKD.45019198 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Agent.mskuk
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Ymacco.AA04
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
GDataTrojan.GenericKD.45019198
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Generic.C4264751
ALYacTrojan.GenericKD.45019198
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
ESET-NOD32MSIL/Agent.DEB
TrendMicro-HouseCallTROJ_GEN.R06BC0PLJ20
TencentMsil.Backdoor.Bladabindi.Akyk
IkarusTrojan.MSIL.Agent
FortinetW32/Bladabindi!tr.bdr
BitDefenderThetaGen:NN.ZemsilCO.34700.am0@aGSpFVc
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
Qihoo-360Generic/Backdoor.633

How to remove MSIL/Agent.DEB?

MSIL/Agent.DEB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment