Malware

MSIL/Agent.CWR removal instruction

Malware Removal

The MSIL/Agent.CWR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.CWR virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Agent.CWR?


File Info:

crc32: 2C8149EF
md5: 1276e815c54ab13a18f21118dd3c6bbb
name: 1276E815C54AB13A18F21118DD3C6BBB.mlw
sha1: 9202801947ebf5b8d5442aaee94d5e32c4c02d20
sha256: d2d5f495be99faf5dcc31f16b20d08b31802215621595e3ffe3a56a2f69c5817
sha512: 1255bf83acaa32faaa152f466b917111f901de3230dcc283d65e03382bacb9118c5cc2d11a7c7904f0d3e9ac44ee9ef7c7bafca56ca65f1a5a4843ed8a4c23a7
ssdeep: 1536:W85j51OntvCY0GW/DkhglxD4wlfVeE6QlAy8VB9qgCzn6OF8ZJjpIDv:rH4tvCY0G0jEwlkzrVB0gM6C8Z9pID
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/Agent.CWR also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.947ebf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.CWR
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34692.giW@aOk0Xmb
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.1276e815c54ab13a
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Backdoor.LimeBak.CJDXDO
AhnLab-V3Trojan/Win32.Genome.C138363
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Agent.CWR?

MSIL/Agent.CWR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment