Malware

MSIL/Agent.UMQ removal instruction

Malware Removal

The MSIL/Agent.UMQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.UMQ virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Agent.UMQ?


File Info:

crc32: 4CC0D5BE
md5: 548c717c98cbaf729e163f194eaea690
name: 548C717C98CBAF729E163F194EAEA690.mlw
sha1: 153126fd7206093e66dd7c4ae754b2fdcabf8f7a
sha256: fcba6d34c31df5303929ae6fa59910a8b24ee98ea7ce97975121c6304a66fa5a
sha512: c74bb797296c1a3a56ce853859ed28cac4f56d90eba4b22113390030ad94fae7256070c2e1ff4dab76abd2ef40fb3009be4814b64585b3793693c269c53606a4
ssdeep: 3072:DlFZZnOPztlcgMtClaC4ViHPjXylsbub:90BlcgMtClaCfPrysb
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: HoldSoft xa9 2021
Assembly Version: 1.0.0.0
InternalName: HoldSoft.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: HoldSoft
ProductVersion: 1.0.0.0
FileDescription: HoldSoft
OriginalFilename:
Translation: 0x0000 0x04b0

MSIL/Agent.UMQ also known as:

BkavW32.HakCookND.Spyware
K7AntiVirusTrojan ( 0057d2711 )
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
CylanceUnsafe
ZillyaTrojan.ClipBanker.Win32.10492
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.37009181
K7GWTrojan ( 0057d2711 )
Cybereasonmalicious.d72060
BitDefenderThetaGen:NN.ZemsilF.34738.km0@aCVBp0b
CyrenW32/Trojan.IORA-4388
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Agent.UMQ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Banker.MSIL.ClipBanker.ps
AlibabaTrojanBanker:MSIL/ClipBanker.7686b709
MicroWorld-eScanTrojan.GenericKD.37009181
TencentMsil.Trojan-banker.Clipbanker.Svhs
Ad-AwareTrojan.GenericKD.37009181
SophosMal/Generic-S
DrWebTrojan.PWS.Stealer.30554
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-FCZG!548C717C98CB
FireEyeGeneric.mg.548c717c98cbaf72
EmsisoftTrojan.GenericKD.37009181 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Kryptik.qmczs
Antiy-AVLTrojan/Generic.ASMalwS.334ED12
ArcabitTrojan.Generic.D234B71D
AegisLabTrojan.MSIL.ClipBanker.7!c
GDataTrojan.GenericKD.37009181
AhnLab-V3Trojan/Win.Agent.C4504705
VBA32CIL.HeapOverride.Heur
MAXmalware (ai score=87)
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R06CC0PF121
YandexTrojan.PWS.ClipBanker!UihJaUOd9pI
IkarusTrojan.MSIL.Agent
FortinetMSIL/GenKryptik.EWGN!tr
PandaTrj/GdSda.A

How to remove MSIL/Agent.UMQ?

MSIL/Agent.UMQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment