Malware

About “MSIL/Agent.VOK” infection

Malware Removal

The MSIL/Agent.VOK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.VOK virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/Agent.VOK?


File Info:

name: FA259965ACDB37DD639D.mlw
path: /opt/CAPEv2/storage/binaries/97c834e0d702f385f16dc29acae830458b672bbad96a0add00c1df364b60aacb
crc32: 87B49567
md5: fa259965acdb37dd639d77e827a17fdd
sha1: 4a4ffa6c32969ea21a9c8700e5005da6589e2cb3
sha256: 97c834e0d702f385f16dc29acae830458b672bbad96a0add00c1df364b60aacb
sha512: 058d24db4ca84ad9da8fbbbe81f21043b5ceee6ff755c848510ab9877cb4c4185f9f67f64f49c6838a9f5a4a51b9841850950afe7d288d968e4b67014313eb2f
ssdeep: 24576:9ipMDaZFUj0KICBBBYvJHjdk6kMRbXerSIlIkYYDx:0aaZxCuBHPfbb/YDx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T141456A827FC5991BC91F4F3699624654A7F8E905A747F74B7C8033EC2C863AC9C422E6
sha3_384: 0b09351ba3d3deb5578dd3cef14bdfbe0632da3c326c9d99612da404297c69dab8e458144de7101e15116b844a3a1197
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-02-15 16:23:03

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: PenterWare.exe
LegalCopyright:
OriginalFilename: PenterWare.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/Agent.VOK also known as:

BkavW32.AIDetectMalware.CS
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
ClamAVWin.Malware.Msilmamut-9974990-0
FireEyeGeneric.mg.fa259965acdb37dd
SkyhighBehavesLike.Win32.Trojan.th
Cylanceunsafe
SangforRansom.Msil.Agent.Vcs6
K7AntiVirusTrojan ( 005956f01 )
AlibabaRansom:MSIL/PenTera.a0cfc528
K7GWTrojan ( 005956f01 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Ransom.REntS.Gen.1
BitDefenderThetaGen:NN.ZemsilF.36744.ln0@aC9shGn
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.VOK
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Heur.Ransom.REntS.Gen.1
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Trojan.Agent.Hkjl
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
F-SecureHeuristic.HEUR/AGEN.1305750
VIPREGen:Heur.Ransom.REntS.Gen.1
TrendMicroRansom_PenTera.R03BC0DBK24
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1305750
MAXmalware (ai score=83)
Kingsoftmalware.kb.c.1000
MicrosoftRansom:MSIL/PenTera.F!MSR
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataGen:Heur.Ransom.REntS.Gen.1
VaristW32/A-8f5775ec!Eldorado
AhnLab-V3Trojan/Win.Generic.R491781
McAfeeArtemis!FA259965ACDB
MalwarebytesTrojan.Crypt.MSIL
TrendMicro-HouseCallRansom_PenTera.R03BC0DBK24
RisingTrojan.Agent!8.B1E (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.VOK!tr.ransom
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove MSIL/Agent.VOK?

MSIL/Agent.VOK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment