Spy

MSIL/Spy.Agent.BIO malicious file

Malware Removal

The MSIL/Spy.Agent.BIO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.BIO virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image

Related domains:

api.telegram.org

How to determine MSIL/Spy.Agent.BIO?


File Info:

crc32: 31AA0833
md5: 1829627e96f32c0aee2efbb704080d88
name: 1829627E96F32C0AEE2EFBB704080D88.mlw
sha1: 173e49cf1ab0f10daae89b58bcc0d642fe905ced
sha256: 89d029dfb108cf275e1e09cfe7e5b012cb3033f8cb59544704d65654d77beb12
sha512: 942acf05a6202e42a4a77e620e1ab3ae568c056cb3bf0a457270b556a465481c51b14997ee0fd13a8eeca4808ac02512bd29028b8f8bc532066ea4dff81557e1
ssdeep: 12288:38Gj11/IH1C2kp64AXhQJl2Nw+1iKG0gHvf:38GR1/gfkp64ARaT+4KG0gn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: Teleshadow Paylaod V2.0.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Teleshadow Paylaod V2.0
ProductVersion: 1.0.0.0
FileDescription: Teleshadow Paylaod V2.0
OriginalFilename: Teleshadow Paylaod V2.0.exe

MSIL/Spy.Agent.BIO also known as:

K7AntiVirusSpyware ( 00523c611 )
LionicTrojan.MSIL.Agent.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Sigmal.S2650633
ALYacGen:Variant.MSILHeracles.22008
CylanceUnsafe
ZillyaTrojan.Agent.Win32.873225
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:MSIL/TScope.f18c7d5f
K7GWSpyware ( 00523c611 )
Cybereasonmalicious.e96f32
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.BIO
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.MSIL.Agent.koj
BitDefenderGen:Variant.MSILHeracles.22008
NANO-AntivirusTrojan.Win32.Mlw.ezncfc
MicroWorld-eScanGen:Variant.MSILHeracles.22008
TencentMalware.Win32.Gencirc.10c8e647
Ad-AwareGen:Variant.MSILHeracles.22008
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34236.Lm1@aiY!Z0o
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PJP21
McAfee-GW-EditionGenericRXDJ-YA!1829627E96F3
FireEyeGeneric.mg.1829627e96f32c0a
EmsisoftGen:Variant.MSILHeracles.22008 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.MSIL.aiqh
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.22E2788
MicrosoftTrojan:Win32/Occamy.C89
GDataGen:Variant.MSILHeracles.22008
AhnLab-V3Malware/Win32.RL_Generic.R264093
McAfeeGenericRXDJ-YA!1829627E96F3
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Agent.MSIL
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PJP21
YandexTrojanSpy.Agent!toyBdPC/o6k
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.73621561.susgen
FortinetMSIL/Agent.BIO!tr.spy
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Spy.Agent.BIO?

MSIL/Spy.Agent.BIO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment