Malware

MSIL/Agent.RVQ information

Malware Removal

The MSIL/Agent.RVQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.RVQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com

How to determine MSIL/Agent.RVQ?


File Info:

crc32: 94881E7E
md5: 07f21e85dca97127a857d04485c490a5
name: tvint1_1_setup.exe
sha1: fd5f0f8cd5756fa348a43984b11e2b1be1b42e92
sha256: dea9e0a230af7b50ca21e4ec8c16618a6b572c07387ab1916e75f9bdf860de0d
sha512: a328b334749a7383582c7b9b846e45ead90aa6e3f99a37c98ad37d48740b0cad5e5df2b5e84b6e06459d13797af939894f23870ab3fa9e103567c6db628d656b
ssdeep: 393216:ZyPqrZtnV056Beb5xTU1JEycDR1VY31TUG1GO:ntnumJEbdYFTUa7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 IntroZorn
FileDescription: turbo-VINT 1.1 Installation
FileVersion: 1.1
Comments:
CompanyName: xa9 IntroZorn
Translation: 0x0409 0x04e4

MSIL/Agent.RVQ also known as:

SangforMalware
Invinceaheuristic
AlibabaTrojan:MSIL/Generic.22047f64
IkarusTrojan.MSIL.Agent
eGambitUnsafe.AI_Score_95%
ESET-NOD32a variant of MSIL/Agent.RVQ
SentinelOneDFI – Suspicious PE
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
CrowdStrikewin/malicious_confidence_60% (W)

How to remove MSIL/Agent.RVQ?

MSIL/Agent.RVQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment