Malware

About “Troj/MSIL-NQB” infection

Malware Removal

The Troj/MSIL-NQB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/MSIL-NQB virus can do?

  • Network activity detected but not expressed in API logs

How to determine Troj/MSIL-NQB?


File Info:

crc32: 1804C3AE
md5: fd36f4de948559a2b149bd02bc090502
name: peace.exe
sha1: 1ba0dc39c34a9ccc8f3825024504ad74cbde7049
sha256: 3dfdbe5e7f36e5e3e3f90365e76ff6c9064bc5b1eb1bc40e282eaadf115e719b
sha512: e4947ee2d0c8bfaed748a8d0a42dba067689e6701e034feb133f9e755d80679f838d153b8da4cfbcc3da790ebe8882587c36afa88d506c9fd664e57bead4aaf7
ssdeep: 24576:+0CyCjgQIJgGHGgCej7xzRN4PGs/WIs0u:xCyCjg5JgEBzP4PP/WIs0u
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016 - 2019
Assembly Version: 0.0.0.0
InternalName: peace.exe
FileVersion: 7.11.14.18
CompanyName: Aj8&m}X36Sw?-q2B
Comments: Lk6!2T&j=8pD3W-r
ProductName: x/4DP8g-5e&W?6S
ProductVersion: 7.11.14.18
FileDescription: x/4DP8g-5e&W?6S
OriginalFilename: peace.exe

Troj/MSIL-NQB also known as:

MicroWorld-eScanTrojan.GenericKD.42309627
FireEyeGeneric.mg.fd36f4de948559a2
Qihoo-360Generic/Trojan.Dropper.e44
McAfeeArtemis!FD36F4DE9485
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055f7931 )
BitDefenderTrojan.GenericKD.42309627
K7GWTrojan ( 0055f7931 )
BitDefenderThetaGen:NN.ZemsilF.34084.Fn0@ayHeaTk
F-ProtW32/Msil.IFD
SymantecTrojan Horse
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.42309627
KasperskyHEUR:Trojan-Dropper.MSIL.Dapato.gen
AlibabaTrojanDropper:MSIL/Dapato.22cb71d2
TencentWin32.Trojan.Inject.Auto
Endgamemalicious (high confidence)
SophosTroj/MSIL-NQB
TrendMicroTROJ_GEN.R069C0WB120
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.42309627 (B)
IkarusTrojan-Spy.Keylogger.AgentTesla
CyrenW32/Trojan.CNCQ-8500
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Generic.D28597FB
ZoneAlarmHEUR:Trojan-Dropper.MSIL.Dapato.gen
AhnLab-V3Trojan/Win32.MSIL.R316223
ALYacTrojan.GenericKD.42309627
MAXmalware (ai score=99)
Ad-AwareTrojan.GenericKD.42309627
MalwarebytesTrojan.PCrypt.MSIL.Generic
PandaTrj/GdSda.A
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallTROJ_GEN.R069C0WB120
RisingDropper.Dapato!8.2A2 (CLOUD)
SentinelOneDFI – Malicious PE
FortinetMSIL/Injector.URK!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/MSIL-NQB?

Troj/MSIL-NQB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment