Worm

How to remove “VHO:Worm.MSIL.Agent”?

Malware Removal

The VHO:Worm.MSIL.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Worm.MSIL.Agent virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine VHO:Worm.MSIL.Agent?


File Info:

crc32: 5D1670C4
md5: 4bd28f985fe959638943e2ac87530c4c
name: 4BD28F985FE959638943E2AC87530C4C.mlw
sha1: 4faf6a23019aa827838cf0a8b4b9def13a0b5d8b
sha256: d3eb4ca45c2f91be4b05786cfbbba0f938681dab0e9211ce047cad71f2d42808
sha512: 9822a480aa731ab29c9b2dbaf3d805cdb06e9fe6bf3ccd87af89433d2f51d40b0d4c309bdccade80e6289a5311d61f474630f63149a8cec913cf2aacbb12800c
ssdeep: 24576:zjNQN5zRwYEYWrzxBABCj5IfkTabjTB1+IGgkRt0x1Uar2aicJUZa:zGftLWrlByCj5Izbj907xRtiXrD/eZa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VHO:Worm.MSIL.Agent also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject3.3994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
ZonerProbably Heur.ExeHeaderH
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Worm.MSIL.Agent.gen
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.gzW@a0su@hi
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.4bd28f985fe95963
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1141184
Antiy-AVLTrojan/Generic.ASBOL.C669
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.JT.R422006
Acronissuspicious
VBA32Trojan.Inject
MalwarebytesBackdoor.Bladabindi
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
PandaTrj/Genetic.gen

How to remove VHO:Worm.MSIL.Agent?

VHO:Worm.MSIL.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment