Malware

About “MSIL/Agent.LV” infection

Malware Removal

The MSIL/Agent.LV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.LV virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine MSIL/Agent.LV?


File Info:

name: BF74714AAF3D252066F0.mlw
path: /opt/CAPEv2/storage/binaries/08d0598495bc15ff608d4ccce0953c7aaa3cde9b4aaab92fe0c20fafe21ec704
crc32: 51BF1AA1
md5: bf74714aaf3d252066f06b71cd4942ac
sha1: 8ac1c81aaed38de5b4712d8dbd598905972ace6b
sha256: 08d0598495bc15ff608d4ccce0953c7aaa3cde9b4aaab92fe0c20fafe21ec704
sha512: d8c2d52cce18d5dfaad1f1fe64182435bded759de2bf340116873ca0d01ed75cd4c932c3c13c7195758837ce6ecb3478e27a311afb52706cb7a36d9cc2d51c03
ssdeep: 3072:eY5Bybw0rjiUvRpjiUvR63ULQwM9EsngL+0f1Z+SyDffoFobEd:eY6nPzPzQ/9rOfOSyG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12ED38C5137AC434BE4BD4FFA90A4A7022374FA6BAE16CB0E48D5B0452F623D0D951EDB
sha3_384: d546cd2a00055b22d5f0fa4ec34962e713b7e4f7f5e909d4f5b750716d658ca86d97744e427ad1fbcc7d0175bb960f36
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-02-25 13:56:44

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: Microsoft Word Document
FileVersion: 1.0.0.0
InternalName: filescan.exe
LegalCopyright: Microsoft Office Copyright © 2015
OriginalFilename: filescan.exe
ProductName: windowsscan
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Agent.LV also known as:

MicroWorld-eScanIL:Trojan.MSILZilla.8300
FireEyeGeneric.mg.bf74714aaf3d2520
ZillyaTrojan.Agent.Win32.666252
K7AntiVirusUnwanted-Program ( 700000121 )
K7GWUnwanted-Program ( 700000121 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZemsilF.34592.im2@aCzF41
SymantecTrojan.Scarimson!gen1
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.LV
ClamAVWin.Spyware.CrimsonRat-9859243-0
KasperskyTrojan-Downloader.MSIL.Agent.ktw
BitDefenderIL:Trojan.MSILZilla.8300
CynetMalicious (score: 99)
AvastWin32:TrojanX-gen [Trj]
Ad-AwareIL:Trojan.MSILZilla.8300
SophosTroj/Foreign-AF
VIPREIL:Trojan.MSILZilla.8300
SentinelOneStatic AI – Malicious PE
EmsisoftIL:Trojan.MSILZilla.8300 (B)
APEXMalicious
GDataMSIL.Trojan.Crimson.B
JiangminTrojanDownloader.MSIL.nbi
AviraHEUR/AGEN.1203735
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.330C
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C1133191
ALYacIL:Trojan.MSILZilla.8300
MalwarebytesMalware.AI.57849642
RisingBackdoor.Crimson!1.D1A3 (CLASSIC)
IkarusTrojan.Win32.Turla
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Small.AAP!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.aaf3d2
PandaTrj/GdSda.A

How to remove MSIL/Agent.LV?

MSIL/Agent.LV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment