Malware

MSIL/Agent.ACU removal

Malware Removal

The MSIL/Agent.ACU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.ACU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Agent.ACU?


File Info:

crc32: C4C47B50
md5: 99f52f966ef4db9673f32e4fd1d84c7d
name: bitcoins.exe
sha1: 88e92734f14a995f6e3ee275e623ca2269053101
sha256: a947fe028a7f3f534d935fceea3adeacc6f36d376abfc2ac30a3cc4c77c09fd7
sha512: 6d4581bd45bd2b6c02a2021f3d8323e6d8e021a5b3ae6fc79d3e3edce55235f4ea2b67f69c414d8bf448c9483c6a3791966752572b8d0ebf5c7d3996b899c424
ssdeep: 49152:atKKKKK3U3zQb8Mygm/27wiP3zQb8Mygm/27wiftL3zQb8Mygm/27wiZ:8KKKKKYrMytONbrMytONfdrMytON
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2012
Assembly Version: 1.0.0.0
InternalName: Stub.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
LegalTrademarks:
Comments:
ProductName: Client
ProductVersion: 1.0.0.0
FileDescription: Client
OriginalFilename: Stub.exe

MSIL/Agent.ACU also known as:

DrWebTrojan.PWS.Stealer.28139
MicroWorld-eScanGen:Heur.MSIL.Krypt.2
FireEyeGen:Heur.MSIL.Krypt.2
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
Qihoo-360Generic/Backdoor.Spy.f85
McAfeeGenericRXJA-IT!99F52F966EF4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004cd20d1 )
BitDefenderGen:Heur.MSIL.Krypt.2
K7GWTrojan ( 004cd20d1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R007C0DBN20
BitDefenderThetaGen:NN.ZemsilF.34104.7o0@a4akg4o
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
GDataMSIL.Trojan-Spy.Keylogger.I
KasperskyHEUR:Backdoor.MSIL.SpyGate.gen
AlibabaBackdoor:MSIL/SpyGate.a3c7def1
NANO-AntivirusTrojan.Win32.SpyGate.gffeop
AegisLabTrojan.MSIL.SpyGate.m!c
RisingBackdoor.SpyGate!8.E154 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Heur.MSIL.Krypt.2 (B)
F-SecureTrojan.TR/AD.KimsRat.fivja
ZillyaTrojan.Agent.Win32.1167127
McAfee-GW-EditionGenericRXJA-IT!99F52F966EF4
Trapminemalicious.moderate.ml.score
SophosMal/SpyGate-A
IkarusTrojan.MSIL.Agent
CyrenW32/Trojan.QETX-1919
JiangminBackdoor.MSIL.cbmt
WebrootTrojan.Dropper.Gen
AviraTR/AD.KimsRat.fivja
MAXmalware (ai score=82)
Antiy-AVLTrojan[Backdoor]/MSIL.SpyGate
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.MSIL.Krypt.2
ZoneAlarmHEUR:Backdoor.MSIL.SpyGate.gen
AhnLab-V3Trojan/Win32.RL_HDC.C3532446
VBA32TScope.Trojan.MSIL
Ad-AwareGen:Heur.MSIL.Krypt.2
MalwarebytesTrojan.Agent.Gen
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Agent.ACU
TrendMicro-HouseCallTROJ_GEN.R007C0DBN20
TencentMsil.Backdoor.Spygate.Hxqb
YandexTrojan.Agent!2AZDEnxDuks
SentinelOneDFI – Malicious PE
FortinetMSIL/Agent.YW!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.66ef4d
MaxSecureTrojan.Malware.10118638.susgen

How to remove MSIL/Agent.ACU?

MSIL/Agent.ACU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment