Malware

About “MSIL/Agent.THY” infection

Malware Removal

The MSIL/Agent.THY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.THY virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Agent.THY?


File Info:

crc32: DD8392DB
md5: 5828a92e50847f773904e85878f2fc6a
name: 5828A92E50847F773904E85878F2FC6A.mlw
sha1: 33b4001d291e40fd950e36f3976e99dcef2327be
sha256: 8bc0620aa9e06ff8861c9cbba4ea13329b42b13fe35c9ba35c30580cf27068b3
sha512: d6ec10484ee04b60a5e7a37b319494b9ec11d1fb045ac422c8d70f81d774cd6283a2cb0f58d6aac48ffeceab8adbb0bdc4bcc69465b2217cbe73ad90a5c2db06
ssdeep: 384:IQE2qRnwQ4Dh9c95t5KmbZS+uJGxoptYcFSVc03K:RqZwQ4Dh9c9X5Rb7nx8tYcFSVc6K
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: BuildPacker.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: BuildPacker
ProductVersion: 1.0.0.0
FileDescription: BuildPacker
OriginalFilename: BuildPacker.exe

MSIL/Agent.THY also known as:

K7AntiVirusTrojan ( 005732f31 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.19137
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.398652
ZillyaTrojan.Agent.Win32.2079923
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 005732f31 )
Cybereasonmalicious.e50847
CyrenW32/MSIL_Kryptik.EDT.gen!Eldorado
ESET-NOD32a variant of MSIL/Agent.THY
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Ursu-9794593-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.398652
MicroWorld-eScanGen:Variant.Bulz.398652
Ad-AwareGen:Variant.Bulz.398652
BitDefenderThetaGen:NN.ZemsilF.34790.am0@a8vQ3Bl
McAfee-GW-EditionGenericRXII-LF!5828A92E5084
FireEyeGeneric.mg.5828a92e50847f77
EmsisoftGen:Variant.Bulz.398652 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:MSIL/AntiWD.YA!MTB
ArcabitTrojan.Bulz.D6153C
GDataGen:Variant.Bulz.398652
AhnLab-V3Trojan/Win.LF.C4385804
McAfeeGenericRXII-LF!5828A92E5084
MAXmalware (ai score=87)
MalwarebytesTrojan.Downloader
PandaTrj/GdSda.A
IkarusTrojan-Downloader.MSIL.Tiny
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.THY!tr
AVGWin32:TrojanX-gen [Trj]

How to remove MSIL/Agent.THY?

MSIL/Agent.THY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment