Malware

VirTool:MSIL/Subti.C removal

Malware Removal

The VirTool:MSIL/Subti.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:MSIL/Subti.C virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:MSIL/Subti.C?


File Info:

crc32: 349741E9
md5: a1381dc49e3f1f97086fb6cc9c25488b
name: flash.exe
sha1: e3d75f69735bc581da42dbebbe254949ecbc21c4
sha256: 6cd922324a87287907fccf0aeb42fdc35f6f34614ed2f3e9adf89008f6059de0
sha512: 88f26f81f98a2a1939788dd721520ca6c660db330a5bd11a4382d9eca07cbbe34d8d397d7ff0a4d4bc56865c23a5e7a502b9ef427ed419571f43054a3593255b
ssdeep: 6144:Y8sQAQKTPjQ/MGywoVKDBsp76DI1f6CCFboOhrs6WYYXaae/CAlWT48mItfb43Y:YXQAoMGWuYvOptWRXEqNtwYpWgH9UoD
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: cloudmusic
Assembly Version: 2.5.5.1202
InternalName: cloudmusic.exe
FileVersion: 2.5.5.1202
CompanyName: cloudmusic
LegalTrademarks: cloudmusic
Comments:
ProductName: cloudmusic
ProductVersion: 2.5.5.1202
FileDescription: cloudmusic
OriginalFilename: cloudmusic.exe

VirTool:MSIL/Subti.C also known as:

DrWebTrojan.DownLoader27.60501
MicroWorld-eScanTrojan.GenericKD.32581815
FireEyeGeneric.mg.a1381dc49e3f1f97
CAT-QuickHealTrojan.MsilFC.S6056940
McAfeePWS-FCLD!A1381DC49E3F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusSpyware ( 004bf53c1 )
BitDefenderTrojan.GenericKD.32581815
K7GWSpyware ( 004bf53c1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTSPY_TINCLEX.SM1
BitDefenderThetaGen:NN.ZemsilF.34104.Hm0@aSXBTgm
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTSPY_TINCLEX.SM1
AvastMSIL:Rat-B [Trj]
ClamAVWin.Tool.Quasar-6791498-0
GDataTrojan.GenericKD.32581815
KasperskyHEUR:Trojan-Spy.MSIL.Quasar.gen
AlibabaVirTool:MSIL/Subti.55139cca
NANO-AntivirusTrojan.Win32.Quasar.fxwqrg
AegisLabTrojan.MSIL.Quasar.l!c
RisingBackdoor.Quasar!1.B1DD (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32581815 (B)
ComodoMalware@#3rp3dzfp6110c
F-SecureHeuristic.HEUR/AGEN.1041329
Invinceaheuristic
McAfee-GW-EditionPWS-FCLD!A1381DC49E3F
SophosMal/Zaquar-A
IkarusTrojan.MSIL.Spy
CyrenW32/Trojan.FTLK-6935
JiangminTrojanSpy.MSIL.agrp
MaxSecureTrojan.Malware.73695559.susgen
AviraHEUR/AGEN.1041329
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/MSIL.Quasar
MicrosoftVirTool:MSIL/Subti.C
ArcabitTrojan.Generic.D1F128B7
ZoneAlarmHEUR:Trojan-Spy.MSIL.Quasar.gen
AhnLab-V3Spyware/Win32.Tinclex.C3456143
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.32581815
Ad-AwareTrojan.GenericKD.32581815
MalwarebytesBackdoor.Quasar
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of MSIL/Spy.Agent.AES
TencentMsil.Trojan-spy.Quasar.Lizw
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
FortinetMSIL/Agent.AFK!tr
AVGMSIL:Rat-B [Trj]
Cybereasonmalicious.49e3f1
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.Spy.da2

How to remove VirTool:MSIL/Subti.C?

VirTool:MSIL/Subti.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment