Malware

About “MSIL/Agent.CTU” infection

Malware Removal

The MSIL/Agent.CTU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.CTU virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Agent.CTU?


File Info:

crc32: 8B321A39
md5: 00663da6a7705c6041b3b00e2d1d5879
name: 00663DA6A7705C6041B3B00E2D1D5879.mlw
sha1: b356d0ddcd0ba17e47313c5963fdbd17ba744d62
sha256: 0ada5dcdc8ad5bf5e834f7d6a4f381f91b6a21fe290bd68ad3ef1c3763d3a3de
sha512: bad7de0c92409857aee8df9d98488e92fd996c5588cdfa7bcf313847a4fb300c6a16171956b7b530d24934e63ce8bb5cf1451aee610ff2040e60ef8d8a45fbd5
ssdeep: 3072:jJXwPY8hgnHsgceLF4hNwYbx3l+Jmgl92vK2QQv3X5aK/mD95u8/5:NAA8wHDcsF7Yhz099/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: TelesRamses.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription: Teltool
OriginalFilename: TelesRamses.exe

MSIL/Agent.CTU also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.ClipBankerNET.7
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.MSILPerseus.224403
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.6a7705
CyrenW32/Zbot.AQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.CTU
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefenderGen:Variant.MSILPerseus.224403
MicroWorld-eScanGen:Variant.MSILPerseus.224403
Ad-AwareGen:Variant.MSILPerseus.224403
BitDefenderThetaGen:NN.ZemsilF.34738.im0@aaNhFb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R014C0DF921
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.00663da6a7705c60
EmsisoftGen:Variant.MSILPerseus.224403 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1138205
eGambitUnsafe.AI_Score_97%
MicrosoftPWS:MSIL/AdamantiumTheif.GA!MTB
GDataGen:Variant.MSILPerseus.224403
AhnLab-V3Trojan/Win.AdamantiumTheif.C4521351
McAfeeArtemis!00663DA6A770
MAXmalware (ai score=85)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R014C0DF921
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.CTU!tr
AVGWin32:TrojanX-gen [Trj]

How to remove MSIL/Agent.CTU?

MSIL/Agent.CTU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment