Malware

About “MSIL/Agent.CNY” infection

Malware Removal

The MSIL/Agent.CNY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.CNY virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Agent.CNY?


File Info:

name: 93F8F357CB02F88CBF2B.mlw
path: /opt/CAPEv2/storage/binaries/26e61a975daa187f5940aae068b8064bc4e8ffaa929f95c9dea73f49e27ddbad
crc32: AB2389EB
md5: 93f8f357cb02f88cbf2b9e1284fd37b9
sha1: d68f0e57c0c405a6aec719524b2618c4f49a3bad
sha256: 26e61a975daa187f5940aae068b8064bc4e8ffaa929f95c9dea73f49e27ddbad
sha512: 2b5c11929a3224447acbe61e3f4926ae48810115fe045626dd88873599e7e9b42392e2d5fb3c723c193fff10c39154cec6bd15d753b4d057f8b03702c972cfa8
ssdeep: 49152:w+axysYC6syUkoPaPS2AJNyxUP+MkJyCjA:1tClVkoOSfJNAUWZyC8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15775239893EE4759F2FA6E707964A06184F0BA46EC13D34DF2C0A58C5FB3B05E635E12
sha3_384: 982c0517772aff0f2c268cb22e4a9139eac8dbd2ea4e2810165c29809af17382b0d24a5cc0f3d590ecfb2b65b9dd11ff
ep_bytes: ff250020400000000000000000000000
timestamp: 2038-01-29 01:20:37

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: SiMay.RemoteService.Loader
FileVersion: 1.0.0.0
InternalName: SiMayService.Loader.exe
LegalCopyright: Copyright © 2019
LegalTrademarks:
OriginalFilename: SiMayService.Loader.exe
ProductName: SiMay.RemoteService.Loader
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Agent.CNY also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.MSILHeracles.39813
CAT-QuickHealTrojan.GenericFC.S20327192
McAfeeGenericRXMY-KH!93F8F357CB02
MalwarebytesMalware.AI.3593043922
VIPREGen:Variant.MSILHeracles.39813
K7AntiVirusTrojan ( 00560e131 )
K7GWTrojan ( 00560e131 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/MSIL_Agent.DQM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.CNY
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.SiMay.gen
BitDefenderGen:Variant.MSILHeracles.39813
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.11a2cbe2
EmsisoftGen:Variant.MSILHeracles.39813 (B)
F-SecureHeuristic.HEUR/AGEN.1357738
DrWebTrojan.Siggen17.37265
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.93f8f357cb02f88c
SentinelOneStatic AI – Suspicious PE
GDataMSIL.Backdoor.SiMay.B
GoogleDetected
AviraHEUR/AGEN.1357738
MAXmalware (ai score=84)
Antiy-AVLTrojan[Backdoor]/MSIL.SiMay
ArcabitTrojan.MSILHeracles.D9B85
ZoneAlarmHEUR:Backdoor.MSIL.SiMay.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C4299469
ALYacGen:Variant.MSILHeracles.39813
PandaTrj/GdSda.A
RisingBackdoor.SiMay!8.12641 (TFE:dGZlOgzAOzGKeQNSVg)
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.7cb02f
DeepInstinctMALICIOUS

How to remove MSIL/Agent.CNY?

MSIL/Agent.CNY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment