Spy

MSIL/Spy.Agent.CZU removal tips

Malware Removal

The MSIL/Spy.Agent.CZU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.CZU virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Spy.Agent.CZU?


File Info:

crc32: C70C5EBA
md5: 5b32904c462c29784efb8bf54bb43320
name: 5B32904C462C29784EFB8BF54BB43320.mlw
sha1: 2da3fabaa5590410287177d834c269244f542d1b
sha256: c4b0d280fbc0c8c17425274ee7ae2ea9b5a74e645a797827df92d8eaa8185237
sha512: b7f33024ba0043488b782ea3ff6f2a2b17dd752602a6778f38733bc6cadde5b903eb34a4b0fcd43ffe2a585474034a395f32a968ff1e00bc4ea9a6824ae5f58f
ssdeep: 768:15eSeLnPvcjG1af/m612G0BJXIQ9E40QgnfseaYbj9f7XTQ94gXoj:15lwvqcaf/m9JYLnfH5bjZLTQqUS
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: lol.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: lol.exe

MSIL/Spy.Agent.CZU also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.29796
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MsilFC.S18894616
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c462c2
CyrenW32/MSIL_Agent.BRH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.CZU
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderGen:Heur.MSIL.Bladabindi.1
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
TencentMalware.Win32.Gencirc.10ce32ff
Ad-AwareGen:Heur.MSIL.Bladabindi.1
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZemsilF.34294.dm1@ayGNrNf
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.5b32904c462c2978
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.bdng
AviraTR/Redcap.tvoss
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.3135464
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.MSIL.Bladabindi.1
GDataGen:Heur.MSIL.Bladabindi.1
AhnLab-V3Malware/Gen.RL_Reputation.C4301829
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.TelegramBot
PandaTrj/GdSda.A
YandexTrojan.Redcap!+1nSEP7wGrw
IkarusGen.MSIL.Bladabindi
MaxSecureTrojan.Malware.74396735.susgen
AVGWin32:Malware-gen

How to remove MSIL/Spy.Agent.CZU?

MSIL/Spy.Agent.CZU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment