Crack

MSIL/HackTool.Agent.LQ (file analysis)

Malware Removal

The MSIL/HackTool.Agent.LQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/HackTool.Agent.LQ virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/HackTool.Agent.LQ?


File Info:

name: 399A89DD7BC5F935DBAC.mlw
path: /opt/CAPEv2/storage/binaries/e8041ce2e72431f381f8d6865069f64c2a735a6108e684d437b8ad9d1ed5100a
crc32: 9616A7DA
md5: 399a89dd7bc5f935dbac4b1682279d18
sha1: 9bb0450c62a7d3047fbb49c4b7665e6ae3686fad
sha256: e8041ce2e72431f381f8d6865069f64c2a735a6108e684d437b8ad9d1ed5100a
sha512: 69bbdd7f97d406ac68668061eae1e4c6bd907a095aef6ce4f61d499f19509dfb4dd85951eecae8526a4281fe5cf91febe5498c14053e28b17e7d493729fa2b6f
ssdeep: 1536:luta+bGDqunA4lsEDbDSDRIh1rHG8k6CMDi/156z25:UG2sVuRm1bG8S56zM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BD3C43096FAC414EB1A1570EBD196F480DD4DAECC93021BC16F7E61B6389ECAC27A57
sha3_384: cd2a47a88bf7b5de88fac3ddc7213b1386bad746c8641920827b71d2c2c50d59fdc5adda194c1542911d6ebffc66fca1
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-05-08 06:22:44

Version Info:

Translation: 0x0000 0x04b0
CompanyName: 1047@exploit.im
FileDescription: Masscan_GUI
FileVersion: 1.6.0.0
InternalName: Massscan_GUI.exe
LegalCopyright: 1047@exploit.im
OriginalFilename: Massscan_GUI.exe
ProductName: Masscan_GUI
ProductVersion: 1.6.0.0
Assembly Version: 1.6.0.0

MSIL/HackTool.Agent.LQ also known as:

BkavW32.AIDetectNet.01
MalwarebytesMachineLearning/Anomalous.100%
Cybereasonmalicious.d7bc5f
CyrenW32/MSIL_Kryptik.CRK.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/HackTool.Agent.LQ
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.MSILPerseus.235338
MicroWorld-eScanGen:Variant.MSILPerseus.235338
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:jJoqno/Qk9wvGbiqTj/c6g)
Ad-AwareGen:Variant.MSILPerseus.235338
EmsisoftGen:Variant.MSILPerseus.235338 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.399a89dd7bc5f935
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILPerseus.235338
ArcabitTrojan.MSILPerseus.D3974A
MicrosoftBackdoor:Win32/Bladabindi!ml
ALYacGen:Variant.MSILPerseus.235338
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.34638.im0@aCgj61b
CrowdStrikewin/malicious_confidence_60% (D)

How to remove MSIL/HackTool.Agent.LQ?

MSIL/HackTool.Agent.LQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment