Categories: Spy

a variant of MSIL/Spy.Agent.AES removal guide

The a variant of MSIL/Spy.Agent.AES file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What a variant of MSIL/Spy.Agent.AES virus can do?

  • Freezing computer.
  • New home page in browsers.
  • Ads and pop-ups on desktop and browser.
  • Very slow loading speed of webpages.
  • Computer work slower then usual.

How to determine a variant of MSIL/Spy.Agent.AES?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Win32:PWSX-gen [Trj]

File Info:

Name: sol.exe

Size: 324096

Type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

MD5: cfa83df0b71731bd2056feced61eecbc

SHA1: 5c6bddfc7540c5517c2f3cb809ff26bc23ec02c9

SH256: 84085256399a997ebf0bbea835ea41357395974134b5421a9b27791f2d4270ad

Version Info:

[No Data]

a variant of MSIL/Spy.Agent.AES also known as:

ALYac Gen:Variant.Razy.577898
APEX Malicious
AVG Win32:PWSX-gen [Trj]
Ad-Aware Gen:Variant.Razy.577898
AegisLab Trojan.MSIL.Agent.4!c
AhnLab-V3 Trojan/Win32.AgentTesla.C3468286
Alibaba Backdoor:MSIL/Remcos.7590a0c6
Arcabit Trojan.Razy.D8D16A
Avast Win32:PWSX-gen [Trj]
Avira TR/Dropper.Gen
BitDefender Gen:Variant.Razy.577898
BitDefenderTheta Gen:NN.ZemsilF.32250.tm0@a8AzOYk
CAT-QuickHeal Trojan.MSIL
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.c7540c
Cylance Unsafe
Cyren W32/Azorult.D.gen!Eldorado
DrWeb Trojan.PWS.Stealer.27388
ESET-NOD32 a variant of MSIL/Spy.Agent.AES
Emsisoft Gen:Variant.Ursu.505703 (B)
Endgame malicious (high confidence)
F-Prot W32/Azorult.D.gen!Eldorado
F-Secure Trojan.TR/Dropper.Gen
FireEye Generic.mg.cfa83df0b71731bd
Fortinet MSIL/Agent.AES!tr.spy
GData Gen:Variant.Razy.577898
Ikarus Trojan.MSIL.Spy
Invincea heuristic
Jiangmin Trojan.MSIL.nito
K7AntiVirus Trojan ( 700000121 )
K7GW Trojan ( 700000121 )
Kaspersky HEUR:Trojan.MSIL.Agent.gen
MAX malware (ai score=80)
Malwarebytes Spyware.AgentTesla.MSIL
MaxSecure Trojan.Malware.300983.susgen
McAfee GenericRXII-SF!CFA83DF0B717
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
MicroWorld-eScan Gen:Variant.Razy.577898
Microsoft Backdoor:MSIL/Remcos!MTB
Paloalto generic.ml
Panda Trj/GdSda.A
Qihoo-360 Win32/Trojan.289
Rising Spyware.AgentTesla!1.B864 (CLASSIC)
SentinelOne DFI – Malicious PE
Sophos Mal/Generic-S
Symantec ML.Attribute.HighConfidence
Trapmine malicious.moderate.ml.score
TrendMicro TROJ_GEN.R04AC0DK819
TrendMicro-HouseCall TROJ_GEN.R04AC0DK819
VIPRE Trojan.Win32.Generic!BT
ZoneAlarm HEUR:Trojan.MSIL.Agent.gen

How to remove a variant of MSIL/Spy.Agent.AES?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

21 hours ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

21 hours ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

21 hours ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

21 hours ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

21 hours ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

21 hours ago