Spy

What is “MSIL/Spy.Agent.CEL”?

Malware Removal

The MSIL/Spy.Agent.CEL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.CEL virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Spy.Agent.CEL?


File Info:

crc32: 199E1BA2
md5: 15515b226f0a764a6a81942609ac8f24
name: winload.exe
sha1: c0a4b7232d62abac2d59682c9be4b18c1a900196
sha256: 7bb576bc8c8bae8e345486e7bad9aa40a261e713f2ece51effd2a00c5cefbec2
sha512: eb36582488d5d293db14880d590c1e2ba63b7f17606df8f02bd09b7ad4ad14ad8405f9c13159c5610e62b490acd6c82196555b94dc42287088d79c9afe96a80b
ssdeep: 6144:hVy9fXp1KgPsez0n9HWxz9yExEdP52H266J:v4f5AkRDho
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corpotation, 2020
Assembly Version: 10.0.18463.127
InternalName: winload.exe
FileVersion: 10.0.18463.127
CompanyName: xa9 Microsoft Corpotation, 2020
LegalTrademarks: xa9 Microsoft Corpotation, 2020
Comments: OS loader
ProductName: Loader OS windows
ProductVersion: 10.0.18463.127
FileDescription: WinLoad
OriginalFilename: winload.exe

MSIL/Spy.Agent.CEL also known as:

MicroWorld-eScanTrojan.GenericKD.43333598
FireEyeGeneric.mg.15515b226f0a764a
CAT-QuickHealTrojanpws.Msil
Qihoo-360Generic/Trojan.PSW.c9f
McAfeeRDN/Generic PWS.y
CylanceUnsafe
AegisLabTrojan.MSIL.Stelega.i!c
SangforMalware
K7AntiVirusSpyware ( 005572ac1 )
BitDefenderTrojan.GenericKD.43333598
K7GWSpyware ( 005572ac1 )
Cybereasonmalicious.32d62a
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.43333598
KasperskyHEUR:Trojan-PSW.MSIL.Stelega.gen
AlibabaTrojanPSW:MSIL/Stelega.351a43fd
RisingSpyware.Agent!8.C6 (CLOUD)
Ad-AwareTrojan.GenericKD.43333598
EmsisoftTrojan.GenericKD.43333598 (B)
ComodoMalware@#33u1hsaxdegjs
F-SecureTrojan.TR/Spy.Agent.xryxj
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.MSIL.SONBOKLI.USXVPFG20
SophosMal/Generic-S
IkarusTrojan.MSIL.Spy
JiangminTrojan.PSW.MSIL.adyz
WebrootW32.Trojan.Gen
AviraTR/Spy.Agent.xryxj
MAXmalware (ai score=82)
Antiy-AVLTrojan[PSW]/MSIL.Stelega
ArcabitTrojan.Generic.D29537DE
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stelega.gen
MicrosoftTrojan:Win32/CoinMiner.C!cl
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Generic.C4147324
BitDefenderThetaGen:NN.ZemsilF.34130.nq0@ainEQHh
ALYacTrojan.GenericKD.43333598
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Spy.Agent.CEL
TrendMicro-HouseCallTrojan.MSIL.SONBOKLI.USXVPFG20
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.CEL!tr.spy
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.74811258.susgen

How to remove MSIL/Spy.Agent.CEL?

MSIL/Spy.Agent.CEL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment