Malware

How to remove “MSIL:Agent-AQ [Drp]”?

Malware Removal

The MSIL:Agent-AQ [Drp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL:Agent-AQ [Drp] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine MSIL:Agent-AQ [Drp]?


File Info:

name: 9CA135500A6586C6A3BF.mlw
path: /opt/CAPEv2/storage/binaries/b5e3a2e00eda2480e81891f32e4ab79dff2dafb39bd53165846d3e1832c20512
crc32: A3F6C856
md5: 9ca135500a6586c6a3bff80a47a16a09
sha1: 1b078a4d0230bc3b73c28547d25877d655973819
sha256: b5e3a2e00eda2480e81891f32e4ab79dff2dafb39bd53165846d3e1832c20512
sha512: abc9ea5a2d4b0f078bb69743d2ffc54f5d1fba589203ae8ef302d6e53bfad9f644c60b2e69498b21c090e33c6377765b7aa29698b029a53d58651f6885b77abc
ssdeep: 12288:QYq8vAhu0f0SHPpwt6Zf0ID06BdgnHN/RMaPpCaSKnZCM:3qKA4AEErgdRDPpCZKIM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEB4121BB1838B68C4541870D6DB385053F67FE72F33A7862E8D321EA496733AB52E54
sha3_384: 38d9cc5ee4da7180eed35dcbc96dbe6519d4d70e4616b2d9861910875fca28d72ee1f76a7ba203d6b91955c212a48444
ep_bytes: ff250020c50200000000000000000000
timestamp: 2011-01-22 16:51:24

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: syncui
FileVersion: 1.0.0.0
InternalName: syncui.exe
LegalCopyright: Copyright © Microsoft 2010
OriginalFilename: syncui.exe
ProductName: syncui
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL:Agent-AQ [Drp] also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.llMc
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Locky.Gen.1
ClamAVWin.Packed.Generic-9780684-0
FireEyeGeneric.mg.9ca135500a6586c6
SkyhighBackDoor-DKI.gen.cx
McAfeeBackDoor-DKI.gen.cx
Cylanceunsafe
ZillyaTrojan.Refroso.Win32.40248
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0053258a1 )
AlibabaBackdoor:Win32/Refroso.1bfe7ff0
K7GWTrojan ( 0053258a1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Locky.Gen.1
BitDefenderThetaGen:NN.ZemsilF.36680.Hq3@auZIy4fG
VirITTrojan.Win32.Generic.JSZ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.HE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Refroso.bsp
BitDefenderTrojan.Locky.Gen.1
NANO-AntivirusTrojan.Win32.Win32.dcjlyk
AvastMSIL:Agent-AQ [Drp]
TencentWin32.Trojan.Refroso.Dplw
EmsisoftTrojan.Locky.Gen.1 (B)
F-SecureTrojan.TR/Agent.hgnu
DrWebTrojan.Click2.4636
VIPRETrojan.Locky.Gen.1
SophosMal/FauxMS-B
IkarusTrojan.SuspectCRC
WebrootRootkit.Gen
GoogleDetected
AviraTR/Agent.hgnu
Antiy-AVLTrojan/Win32.Llac
KingsoftWin32.Trojan.Refroso.bsp
XcitiumTrojWare.MSIL.TrojanDropper.Agent.YX@4pl6wp
MicrosoftTrojan:Win32/Bifrose
ViRobotTrojan.Win32.Agent.586240.C
ZoneAlarmTrojan.Win32.Refroso.bsp
GDataTrojan.Locky.Gen.1
VaristW32/Agent.KV.gen!Eldorado
AhnLab-V3Trojan/Win32.Dynamer.R5446
VBA32TScope.Trojan.MSIL
ALYacTrojan.Locky.Gen.1
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
RisingMalware.Obfus/MSIL@AI.80 (RDM.MSIL2:WpI4+O+ZT/qhj41DVuGNxw)
YandexTrojan.Refroso!7Vn9kuWHuw8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Refroso.DX!tr
AVGMSIL:Agent-AQ [Drp]
Cybereasonmalicious.d0230b
DeepInstinctMALICIOUS

How to remove MSIL:Agent-AQ [Drp]?

MSIL:Agent-AQ [Drp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment