Spy

How to remove “MSIL/Spy.Agent.DQF”?

Malware Removal

The MSIL/Spy.Agent.DQF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.DQF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Captures Screenshot

How to determine MSIL/Spy.Agent.DQF?


File Info:

name: A77EFE65D58F4E5E35DB.mlw
path: /opt/CAPEv2/storage/binaries/8d3522545e13100b8e3bea7132534b166b66e0e44d4333277d9e7261f26273ee
crc32: FCE011AC
md5: a77efe65d58f4e5e35db5db4d34bac6f
sha1: f56c279ebcaad0cadec6255670e0157176d88778
sha256: 8d3522545e13100b8e3bea7132534b166b66e0e44d4333277d9e7261f26273ee
sha512: 16a6bbe82bae0489071dc6eac1fc4eb0a982ccbb1e96e7f918ba5d9ab9987f74462cbc128376a689c6a0ff15f064fb77bc973fe62cfd0bd6ebc16fc71622b120
ssdeep: 384:9Bnf8q65mncjQalLf45lQfrZGF78Y9BJJ:9BnMMa56FHB3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBE22B2A13AAC373CE6D4B71995323514672DD528612FFAF2D8875BA4CF7B010B037A1
sha3_384: aac78991616859b353deffdfbb0569cdb12db3a6171f1be1ef16bacd4d88357c9f8806335bba7d68c478a256fcaeb7c7
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-21 12:31:19

Version Info:

Translation: 0x0000 0x04b0
FileDescription: upload background
FileVersion: 1.0.0.0
InternalName: FTP-RAT.exe
LegalCopyright: Copyright © 2021
OriginalFilename: FTP-RAT.exe
ProductName: upload background
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Spy.Agent.DQF also known as:

LionicTrojan.MSIL.Small.m!c
MicroWorld-eScanTrojan.GenericKD.47539710
McAfeeArtemis!A77EFE65D58F
CylanceUnsafe
SangforBackdoor.MSIL.Small.gen
K7AntiVirusSpyware ( 0058af191 )
AlibabaBackdoor:MSIL/Generic.b49ee314
K7GWSpyware ( 0058af191 )
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Spy.Agent.DQF
TrendMicro-HouseCallTROJ_GEN.R002C0WKQ21
KasperskyHEUR:Backdoor.MSIL.Small.gen
BitDefenderTrojan.GenericKD.47539710
AvastWin32:Trojan-gen
TencentMsil.Backdoor.Small.Lmuo
Ad-AwareTrojan.GenericKD.47539710
EmsisoftTrojan.GenericKD.47539710 (B)
Comodofls.noname@0
TrendMicroTROJ_GEN.R002C0WKQ21
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.47539710
SophosMal/Generic-S
IkarusTrojan.MSIL.Spy
JiangminBackdoor.MSIL.fgzl
eGambitUnsafe.AI_Score_53%
AviraTR/Spy.Agent.csxdt
Antiy-AVLTrojan/Generic.ASMalwS.34D9C31
MicrosoftTrojan:Win32/Ymacco.AB8D
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.D2D565FE
GDataTrojan.GenericKD.47539710
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4787431
ALYacTrojan.GenericKD.47539710
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.PasswordStealer
APEXMalicious
FortinetMSIL/Agent.DQF!tr.spy
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Spy.Agent.DQF?

MSIL/Spy.Agent.DQF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment