Malware

About “MSIL/Agent.VFA” infection

Malware Removal

The MSIL/Agent.VFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.VFA virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Agent.VFA?


File Info:

name: D65B0BBB2729A5300FC0.mlw
path: /opt/CAPEv2/storage/binaries/b6ba00c0ddaf24e083c51cf1dc68dbd3f883f7176db27cb2cce5aa28e67aebad
crc32: C0F5A7E6
md5: d65b0bbb2729a5300fc0fc0146c982d1
sha1: acfb017465e48ad5f95fa00068b2ee20a4008311
sha256: b6ba00c0ddaf24e083c51cf1dc68dbd3f883f7176db27cb2cce5aa28e67aebad
sha512: 0f1bf25cb59aabb68c10eb9188982934685226f41d34a3787057108878cca5ed2f614dae5eaeec41ae8712eebe19c8842ab3b9b1c75e57088bddf9adda3a135f
ssdeep: 1536:GxalR/rEyJwEfNlcvnPvndendZBklnbtz/nQbXS+e70P6JSmf+A:O/EfrSPvcdE1tQbXS+e70P6JSmf+A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6C3539E726071DFCD57CC7599A82CA4A630687BA30B9207905315EEDB0E9E7DF180F2
sha3_384: b183ee27bbd4f85af3a14993888dac4f1b2f0c7611a2ae83eab0e466fbf0587738161ef95843a72b2ea8064c76559397
ep_bytes: ff250020400000000000000000000000
timestamp: 2049-06-11 15:14:14

Version Info:

Translation: 0x0000 0x04b0
Comments: Programs Engine
CompanyName: Microsoft® Windows®
FileDescription: Programs Engine
FileVersion: 10.0.19041.746
InternalName: Task32Main.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Task32Main.exe
ProductName: Programs Engine
ProductVersion: 10.0.19041.746
Assembly Version: 10.0.19041.746

MSIL/Agent.VFA also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.MSILHeracles.34622
FireEyeGeneric.mg.d65b0bbb2729a530
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeGenericRXSS-VS!D65B0BBB2729
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058f7721 )
K7GWTrojan ( 0058f7721 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34742.hm0@aSt5OIc
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.VFA
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.MSILHeracles.34622
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.MSILHeracles.34622
EmsisoftGen:Variant.MSILHeracles.34622 (B)
McAfee-GW-EditionGenericRXSS-VS!D65B0BBB2729
SophosGeneric ML PUA (PUA)
GDataGen:Variant.MSILHeracles.34622
WebrootTrojanSpy:Win32/Webmoner
MAXmalware (ai score=82)
ArcabitTrojan.MSILHeracles.D873E
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32CIL.HeapOverride.Heur
ALYacGen:Variant.MSILHeracles.34622
MalwarebytesBackdoor.DCRat
APEXMalicious
SentinelOneStatic AI – Suspicious PE
AVGWin32:TrojanX-gen [Trj]

How to remove MSIL/Agent.VFA?

MSIL/Agent.VFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment