Malware

MSIL/Agent.VDI removal instruction

Malware Removal

The MSIL/Agent.VDI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.VDI virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Agent.VDI?


File Info:

name: D916685FCE612183E88C.mlw
path: /opt/CAPEv2/storage/binaries/fe916d2ddcdd22ff2f1d7f2546daa61ba8edf7dead1d2cae6853a94f38282b54
crc32: E6DB5910
md5: d916685fce612183e88cb13877672781
sha1: e192614d17c4e1a5accfbb0137206f0ce3406082
sha256: fe916d2ddcdd22ff2f1d7f2546daa61ba8edf7dead1d2cae6853a94f38282b54
sha512: be4c4d2fbfaf57544d42b90e337ee311d24e8bf3b8e20aa8ba1e31f14c173c1da00778f5b414b013b42eaf82f09929a3940c3555eaa5585846b3f8957c4d80d5
ssdeep: 192:Nzw5STpX4094TtGFF8vkYcV6PU2FJFEs2+:0STgRGFF6kYcV6PUiJFnh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB22B91042D54076D13196726D55BF09FFBB8ABF2E56826A344C592F3FB3120C7236BA
sha3_384: 895a1b468710582ddabec712fa33cb5f7f24354ba8e0de91cae05c14d76db95e36890860c47be8681c66401336c64e04
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-11 19:48:47

Version Info:

Translation: 0x0000 0x04b0
CompanyName: MsMpEng
FileDescription: RatNewGen
FileVersion: 0.1.0.0
InternalName: RatNewGen.exe
LegalCopyright:
OriginalFilename: RatNewGen.exe
ProductName: MsMpEng
ProductVersion: 0.1.0
Assembly Version: 0.1.0.0

MSIL/Agent.VDI also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.48330480
FireEyeGeneric.mg.d916685fce612183
McAfeeRDN/Generic Exploit
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2678729
SangforExploit.MSIL.ShellCode.gen
AlibabaExploit:MSIL/ShellCode.d0191517
BitDefenderThetaGen:NN.ZemsilF.34232.am0@aijxb!f
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Agent.VDI
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Exploit.MSIL.ShellCode.gen
BitDefenderTrojan.GenericKD.48330480
TencentMsil.Exploit.Shellcode.Wqcs
Ad-AwareTrojan.GenericKD.48330480
SophosMal/Generic-S (PUA)
TrendMicroTROJ_GEN.R002C0PBF22
McAfee-GW-EditionRDN/Generic Exploit
EmsisoftTrojan.GenericKD.48330480 (B)
IkarusTrojan.MSIL.Agent
GDataTrojan.GenericKD.48330480
AviraTR/Agent.pekxj
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=80)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PBF22
RisingTrojan.Generic/MSIL@AI.90 (RDM.MSIL:D4bTpXja/X9Iwb0EnUjTuw)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.VDI!tr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Agent.VDI?

MSIL/Agent.VDI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment