Spy

What is “MSIL/Spy.Agent.AUM”?

Malware Removal

The MSIL/Spy.Agent.AUM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.AUM virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/Spy.Agent.AUM?


File Info:

crc32: 4A1C9302
md5: e7abf5ebe18f680df3af25745fecd7c4
name: E7ABF5EBE18F680DF3AF25745FECD7C4.mlw
sha1: c84b6a27348cb3b419885cfce5c31e1dbd307c44
sha256: 0390e409ffa9fdbf0a37c5366da50cb4021f3be254dbbe03f683151612b1b526
sha512: 7a98f47081f72e24f4a7c9ce79c72f3aebcfe822b8dfc5007fc2b3be4637ecc7474f04d31c2c3ed8ea4ac3747925eceeb9c45f82119f73ebe4d49d4bcf3b5c86
ssdeep: 192:MJ8YoHq5wztJr6dFsoMCCJa48PdatJYw76mcWGD7r8C3oa:6wpOFsx8Pdatiwmm47no
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: Koolova Keylogger.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Koolova Keylogger
ProductVersion: 1.0.0.0
FileDescription: Koolova Keylogger
OriginalFilename: Koolova Keylogger.exe

MSIL/Spy.Agent.AUM also known as:

LionicTrojan.Win32.Generic.4!c
CylanceUnsafe
ZillyaTrojan.Agent.Win32.901930
SangforTrojan.MSIL.KeyLogger.gen
Cybereasonmalicious.7348cb
CyrenW32/Keylogger.AG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.AUM
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Spy.MSIL.KeyLogger.gen
NANO-AntivirusTrojan.Win32.Mlw.fekkvz
TencentWin32.Trojan.Spy.Alsl
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34266.am0@aiCtJqk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.e7abf5ebe18f680d
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.26B15BB
MicrosoftBackdoor:Win32/Bladabindi!ml
McAfeeArtemis!E7ABF5EBE18F
MAXmalware (ai score=95)
MalwarebytesTrojan.KeyLogger
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Spy
FortinetMSIL/Agent.AUM!tr.spy
AVGWin32:Malware-gen

How to remove MSIL/Spy.Agent.AUM?

MSIL/Spy.Agent.AUM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment