Malware

What is “MSIL/Agent.SPS”?

Malware Removal

The MSIL/Agent.SPS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.SPS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Detects Sunbelt Sandbox through the presence of a file
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a file
  • Detects VMware through the presence of a registry key

Related domains:

z.whorecord.xyz
a.tomx.xyz
hexui.com

How to determine MSIL/Agent.SPS?


File Info:

crc32: 5021788B
md5: b7d491a3ffc372a9d023f055b324bf13
name: B7D491A3FFC372A9D023F055B324BF13.mlw
sha1: 9ea3ab0bbde11f2fc0e2eec5162edf09f4c2c29f
sha256: 2c6146b1294b553983e0fe7d3bbd1badf85da9f7404b402049749426543190bd
sha512: b14a3d02b729e7c5854c12b8a12b8ef7b4d4f32899c4ec4728dc5b7c548a282840ad52053b38fb4bdac25a3590049b373283873ab3b61f7e3c951ed45930c74d
ssdeep: 3072:3z1NZ9rUXaVdEesB/KxaaKWZSxk+H4j7rk8:hNDUX3estKx6k+HSrk8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/Agent.SPS also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30978370
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3ffc37
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.SPS
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.30978370
NANO-AntivirusTrojan.Win32.Mlw.fehelo
MicroWorld-eScanTrojan.GenericKD.30978370
TencentWin32.Trojan.Generic.Phzw
Ad-AwareTrojan.GenericKD.30978370
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34170.imX@a8tOS1h
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.b7d491a3ffc372a9
EmsisoftTrojan.GenericKD.30978370 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Refroso.hvj
AviraHEUR/AGEN.1122169
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.26A1532
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.30978370
Acronissuspicious
McAfeeArtemis!B7D491A3FFC3
MAXmalware (ai score=94)
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/GdSda.A
YandexTrojan.Agent!fatK4Kuf39I
IkarusTrojan.MSIL.Agent
FortinetMSIL/Agent.SPS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Agent.SPS?

MSIL/Agent.SPS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment