Spy

What is “MSIL/Spy.Agent.BYW”?

Malware Removal

The MSIL/Spy.Agent.BYW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.BYW virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Spy.Agent.BYW?


File Info:

crc32: 28DA5A79
md5: 4eb5cbef221e5536af1caa27e23a2abf
name: upload_file
sha1: 71eec8154b8b19f88c1385a77394b26422f53735
sha256: 54d7969a09d2ad3dcf82a96a0fce4e3fc5bbb6ee26d01a0b8517f364b5431217
sha512: ef5a8aca4efe04acc1dd8fea024ba8ddfd354d59c491ff1119fa97f6e3f037f2baead8498689f07724ff9c80b97f1a51ff060471c4f0f99b0ec4deb89896baee
ssdeep: 24576:+mr2fNL6dNUtlffkPNeL289e4NoMTro22D:WfNL6dNUtlXo4Sbh
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft xa9 2019
Assembly Version: 1.0.0.0
InternalName: Stubv4.0.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
Assembly Copyright: Microsoft xa9 2019
ProductVersion: 1.0.0.0
FileDescription: Microsoft Application
OriginalFilename: 2323.exe

MSIL/Spy.Agent.BYW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Krypt.2
FireEyeGeneric.mg.4eb5cbef221e5536
ALYacGen:Heur.MSIL.Krypt.2
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:MSIL/Quasar.98ecfe64
K7GWSpyware ( 0054b33f1 )
K7AntiVirusSpyware ( 0054b33f1 )
InvinceaMal/Generic-S
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Quasar.gen
BitDefenderGen:Heur.MSIL.Krypt.2
Ad-AwareGen:Heur.MSIL.Krypt.2
EmsisoftTrojan-Spy.Agent (A)
ComodoMalware@#39ud2b8ra9jew
F-SecureTrojan.TR/Spy.Agent.qqkjj
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R02FC0WIP20
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
GDataGen:Heur.MSIL.Krypt.2
JiangminTrojanSpy.MSIL.axxy
AviraTR/Spy.Agent.qqkjj
MAXmalware (ai score=86)
Antiy-AVLTrojan[Spy]/MSIL.Quasar
ArcabitTrojan.MSIL.Krypt.2
AegisLabTrojan.MSIL.Quasar.l!c
ZoneAlarmHEUR:Trojan-Spy.MSIL.Quasar.gen
MicrosoftTrojan:Win32/Ymacco.AA54
McAfeeArtemis!4EB5CBEF221E
MalwarebytesBackdoor.Quasar
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Spy.Agent.BYW
TrendMicro-HouseCallTROJ_GEN.R02FC0WIP20
TencentMsil.Trojan-spy.Quasar.Phgv
IkarusTrojan.MSIL.Spy
FortinetW32/Quasar.BYW!tr
BitDefenderThetaGen:NN.ZemsilF.34254.hn0@a0wOaTn
AVGWin32:Trojan-gen
Cybereasonmalicious.f221e5
Qihoo-360Generic/Trojan.Spy.da2

How to remove MSIL/Spy.Agent.BYW?

MSIL/Spy.Agent.BYW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment