Spy

How to remove “MSIL/Spy.Agent.DPE”?

Malware Removal

The MSIL/Spy.Agent.DPE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.DPE virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Spy.Agent.DPE?


File Info:

name: 231A9A617F1CF8176DD1.mlw
path: /opt/CAPEv2/storage/binaries/2b9441c41ab0053eb0a8a4dd3a1d8357cf58d29b1c95e542f34e3bc3d81465c3
crc32: 245EB848
md5: 231a9a617f1cf8176dd1835570f65cfd
sha1: ead4c1cbbb121b49fcc9561eafa61522b66c4f98
sha256: 2b9441c41ab0053eb0a8a4dd3a1d8357cf58d29b1c95e542f34e3bc3d81465c3
sha512: 3ad807f3fc7687539194f458078fb3cfa4571e885208679465c6099e387e1249a758ea54146647a732d6e2def41c2bd197cfa355ebda1744a05648f58d18724f
ssdeep: 96:jfIx6qHc9lXjeBJhy0Na/lugk5PteAkVczNt:TIx/H4iJdlH5PEM
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T122C1B51163F88735E9B69B7AAC7343004675B7514C73CB6E38CC615BAD27B248B22B71
sha3_384: c9c3c70706f1ee3648b5512b2d86e0547e12485333f3906ab777258a55857ad61346950982be93c675a76da52abc4fa7
ep_bytes: ff250020400000000000000000000000
timestamp: 2040-09-22 20:45:49

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Amongus
FileVersion: 1.0.0.0
InternalName: Amongus.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Amongus.exe
ProductName: Amongus
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Spy.Agent.DPE also known as:

LionicTrojan.MSIL.Agent.4!c
DrWebTrojan.SpyBot.1125
MicroWorld-eScanIL:Trojan.MSILZilla.6004
FireEyeIL:Trojan.MSILZilla.6004
McAfeeRDN/Generic.dx
MalwarebytesRiskWare.Agent
ZillyaTrojan.Agent.Win32.2534386
K7AntiVirusSpyware ( 00589ec61 )
AlibabaTrojan:MSIL/MSILZilla.6141df35
K7GWSpyware ( 00589ec61 )
Cybereasonmalicious.17f1cf
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Spy.Agent.DPE
TrendMicro-HouseCallTROJ_GEN.R002C0PK421
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderIL:Trojan.MSILZilla.6004
AvastWin32:TrojanX-gen [Trj]
Ad-AwareIL:Trojan.MSILZilla.6004
EmsisoftTrojan-Spy.Agent (A)
TrendMicroTROJ_GEN.R002C0PK421
McAfee-GW-EditionRDN/Generic.dx
SophosMal/Generic-S
IkarusTrojan.IL.MSILZilla
GDataIL:Trojan.MSILZilla.6004
AviraTR/Spy.Agent.pgaef
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Agent.6144.CII
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4750376
ALYacIL:Trojan.MSILZilla.6004
MAXmalware (ai score=88)
CylanceUnsafe
APEXMalicious
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A

How to remove MSIL/Spy.Agent.DPE?

MSIL/Spy.Agent.DPE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment