Malware

MSIL/Agent.UTP (file analysis)

Malware Removal

The MSIL/Agent.UTP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Agent.UTP virus can do?

  • Authenticode signature is invalid

How to determine MSIL/Agent.UTP?


File Info:

name: EAF2BBD298D88E835332.mlw
path: /opt/CAPEv2/storage/binaries/e7c582be6c599ae1ef3a93dc6ee90154ee6230a177637e3a3be66614eba50673
crc32: CFD39540
md5: eaf2bbd298d88e835332d7ea3e10ab43
sha1: 036aa3549f07ec6cd472d6c45890a68a89ff4207
sha256: e7c582be6c599ae1ef3a93dc6ee90154ee6230a177637e3a3be66614eba50673
sha512: f7ccb1a61b8f07e94085f453df3d050af99c6530ac9dfd85aab3ec10270596532aeff9534672c58795f3f1e11f178cef3cc841f9f1875bff8b47a18406ced9d0
ssdeep: 1536:qLRUnaqgCrtAnlmWzVt3A7HPd4n+lbeRZIbSQPTf:UO4lvzHQbPRyZ2pPTf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11983BE923305D5B1CF4C07B0E8B34AACA5B0ADF44E4467267D88FAEF3DB0759560AB84
sha3_384: bf3a055c81e537885af082dfaaa8b2083b269a96ef7ff0ecedb24b6382fbc8aaa8e2f1297cfef24e725a8faca69203ef
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-11-21 13:17:24

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Print driver host for applications
FileVersion: 10.0.17763.1339 (WinBuild.160101.0800)
InternalName: splwow64.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: splwow64.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17763.1339
Translation: 0x0409 0x04b0

MSIL/Agent.UTP also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Agent.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.eaf2bbd298d88e83
SkyhighBehavesLike.Win32.Generic.mh
ALYacTrojan.Dropper.Agent
Cylanceunsafe
ZillyaTrojan.Agent.Win32.2015147
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Generic.0731e70a
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZemsilF.36744.fm0@aieFjhgi
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Agent.UTP
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Agent.gen
AvastWin32:Malware-gen
RisingDropper.Generic!8.35E (C64:YzY0OoZyUNYV06u0)
F-SecureTrojan.TR/Dropper.Gen
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.ynqa
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Generic
Kingsoftmalware.kb.c.1000
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.C4272657
McAfeeArtemis!EAF2BBD298D8
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
TencentMsil.Trojan.Agent.Tsmw
YandexTrojan.DR.Agent!YYeGbXSM6w8
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.8703358.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Agent.UTP?

MSIL/Agent.UTP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment