Spy

MSIL/Spy.Agent.APY removal instruction

Malware Removal

The MSIL/Spy.Agent.APY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.APY virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
mscloud.aion.feralhosting.com
mscloud.pallas.feralhosting.com

How to determine MSIL/Spy.Agent.APY?


File Info:

crc32: EE4E247A
md5: cbc10bc4b91e5f8ff5d8188123e72094
name: setup.exe
sha1: 3149870ce835bcc3ea3f150a1d4635d5fb8efa1c
sha256: c75dc1b4b2f949105328de310c2f5bdd540a4a4314e476269c5f87e3ce4af44c
sha512: df36827b28dedc83fb1eec664827310bac18ca9f2a9392b190316f8c1bff679467aa6e0353f96e48641d57f7a1243a39e398d314fabc404c29ced96a3dabb20c
ssdeep: 24576:U7blvVNOEusFS5MYxMtME9rq8Or3DFM7dei:U75vVNzqMYxjE9rq8Ofyoi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName:
ProductVersion:
FileDescription:
Translation: 0x0000 0x04b0

MSIL/Spy.Agent.APY also known as:

MicroWorld-eScanTrojan.GenericKD.30830356
CAT-QuickHealTrojan.Dynamer
McAfeeArtemis!CBC10BC4B91E
K7GWSpyware ( 004f79bb1 )
K7AntiVirusSpyware ( 004f79bb1 )
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DEK18
AvastWin32:Malware-gen
GDataTrojan.GenericKD.30830356
KasperskyHEUR:Trojan-Dropper.Win32.Generic
BitDefenderTrojan.GenericKD.30830356
NANO-AntivirusTrojan.Win32.Mlw.fcefye
AegisLabTroj.Dropper.W32!c
TencentWin32.Trojan-dropper.Generic.Tcbx
Ad-AwareTrojan.GenericKD.30830356
SophosMal/Generic-S
ComodoUnclassifiedMalware
F-SecureTrojan.GenericKD.30830356
DrWebTrojan.DownLoader26.51808
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DEK18
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.th
EmsisoftTrojan.GenericKD.30830356 (B)
IkarusTrojan.MSIL.Spy
CyrenW32/A-17b8a5e1!Eldorado
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1033021
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1D66F14
ZoneAlarmHEUR:Trojan-Dropper.Win32.Generic
MicrosoftTrojan:Win32/Dynamer!rfn
ALYacTrojan.GenericKD.30830356
AVwareTrojan.Win32.Generic!BT
VBA32Trojan.Dynamer
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Spy.Agent.APY
RisingSpyware.Agent!8.C6 (CLOUD)
YandexTrojanSpy.Agent!73x4KnSmioQ
SentinelOnestatic engine – malicious
FortinetW32/Generic.APY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikemalicious_confidence_90% (D)
Qihoo-360Win32/Trojan.5a2

How to remove MSIL/Spy.Agent.APY?

MSIL/Spy.Agent.APY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment