Spy

About “MSIL/Spy.Agent.DTO” infection

Malware Removal

The MSIL/Spy.Agent.DTO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.DTO virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine MSIL/Spy.Agent.DTO?


File Info:

name: 269A8BB6BEDCAF4C164B.mlw
path: /opt/CAPEv2/storage/binaries/6d92b3d772acf6b1583eef109cf8797ebac13fe4b0491b713864252c8bd14b46
crc32: 3561BA2C
md5: 269a8bb6bedcaf4c164b38a390fc975c
sha1: bd13b45d2f80ee84ade5eddee959422b55d0a5df
sha256: 6d92b3d772acf6b1583eef109cf8797ebac13fe4b0491b713864252c8bd14b46
sha512: c4eb2bbb171f7e464dfde465f9662dfdea91fb7d8dbe2a0ae6acdabe5c1c2373ee0f0e670139786ea6e082308b8e7ef2f33561b6d53081af1240652cc6698b64
ssdeep: 24576:PTFKbEN2H69y5SzdWETaUqH2OYv04+ZdQXfcynMV:PBKbEtTaUqH2Of4+/qrM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1420529223A44C942D0699733CAFF485447ECAD427A62DB5A7EAF37AD25123A70C0D5CF
sha3_384: 896a008f86dc446aa3a51b9ebc25e4c2e30225fdba4db298223e09c55a7c9ddb17459900787c0849fa148f7ab5630452
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-20 18:06:21

Version Info:

FileVersion: 2019.4.15.16511847
ProductVersion: 2019.4.15.16511847
Unity Version: 2019.4.15f1_fbf367ac14e9
Translation: 0x0409 0x04b0

MSIL/Spy.Agent.DTO also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Dnoper.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen17.14002
MicroWorld-eScanIL:Trojan.MSILZilla.9872
FireEyeGeneric.mg.269a8bb6bedcaf4c
ALYacIL:Trojan.MSILZilla.9872
MalwarebytesSpyware.PasswordStealer
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0058eb471 )
AlibabaTrojanSpy:Win32/MalwareX.12b98216
K7GWSpyware ( 0058eb471 )
Cybereasonmalicious.6bedca
ArcabitIL:Trojan.MSILZilla.D2690
BitDefenderThetaGen:NN.ZemsilF.34606.Xq0@ayZJ5Qpi
CyrenW32/MSIL_Agent.LQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Spy.Agent.DTO
TrendMicro-HouseCallTROJ_GEN.R002C0PBN22
Paloaltogeneric.ml
ClamAVWin.Packed.Uztuby-9940928-0
KasperskyHEUR:Trojan.MSIL.Dnoper.gen
BitDefenderIL:Trojan.MSILZilla.9872
NANO-AntivirusTrojan.Win32.Dnoper.jmyoau
ViRobotTrojan.Win32.Z.Agent.814592.Z
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Trojan.Dnoper.Hrpi
Ad-AwareIL:Trojan.MSILZilla.9872
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PBN22
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
EmsisoftIL:Trojan.MSILZilla.9872 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.amgsi
AviraHEUR/AGEN.1203070
Antiy-AVLTrojan/Generic.ASMalwS.3537CFE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataIL:Trojan.MSILZilla.9872
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MSILZilla.C4979391
Acronissuspicious
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
APEXMalicious
YandexTrojan.Dnoper!tPdB/9Ll4ZY
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DEK!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Spy.Agent.DTO?

MSIL/Spy.Agent.DTO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment