Spy

MSIL/Spy.Agent.ETF removal

Malware Removal

The MSIL/Spy.Agent.ETF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Agent.ETF virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine MSIL/Spy.Agent.ETF?


File Info:

name: 71F3FF7D24C0A2F4B656.mlw
path: /opt/CAPEv2/storage/binaries/96150c79ad8803ba855ae49143b3a7dc6a4b30abaf2a80c12710fcec90e4f493
crc32: 0427CD15
md5: 71f3ff7d24c0a2f4b6563985d22cdd67
sha1: c6b4116b951badd66361bb32aa027a793d205000
sha256: 96150c79ad8803ba855ae49143b3a7dc6a4b30abaf2a80c12710fcec90e4f493
sha512: 13dba5760ced05751f482a082e15cad397bc393e6a0ac5ea40857191e5a0f6e77d2a7b6fc77b8fc7c28c0489a097c0f4a706a17665079b5e1b9afa61abcc1ef6
ssdeep: 24576:xpbyeteLaJjGT2Yw5F8IRZSc+TqFO8d96w32/pzMLOQRoFUaTVCRIRGmkgh6v9Ej:xweJ68rQc+QXAw4eLOQeFbiI3kgUin
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5A5CF069A524E73C2E8BF3085EB191D42B0C6367522EF0B3A6F6595AD163318F136F7
sha3_384: 60899fa97af922b45284df53ccc9c939f11abb9e467a202fc4ace934d6cf4558544cc49e6fc2445ec2d8c69e0935ca0f
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-09-18 01:48:37

Version Info:

CompanyName:
FileDescription:
FileVersion: 16.10.31418.88
InternalName: VisualStudio.Shell.Framework.dll
LegalCopyright: © All rights reserved.
OriginalFilename: VisualStudio.Shell.Framework.dll
ProductName:
ProductVersion:
Assembly Version: 16.0.0.0
Translation: 0x0000 0x04b0

MSIL/Spy.Agent.ETF also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Basic.4!c
MicroWorld-eScanTrojan.MSIL.Basic.8.Gen
ClamAVWin.Packed.Uztuby-10009381-0
FireEyeGeneric.mg.71f3ff7d24c0a2f4
SkyhighBehavesLike.Win32.Generic.vc
McAfeeArtemis!71F3FF7D24C0
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005690671 )
K7GWTrojan ( 005690671 )
BitDefenderThetaGen:NN.ZemsilF.36744.co0@aylSG!h
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.Agent.ETF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Dnoper.gen
BitDefenderTrojan.MSIL.Basic.8.Gen
AvastWin32:Evo-gen [Trj]
TencentMsil.Trojan.Dnoper.Gkjl
EmsisoftTrojan.MSIL.Basic.8.Gen (B)
F-SecureHeuristic.HEUR/AGEN.1323342
VIPRETrojan.MSIL.Basic.8.Gen
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.MSIL.Basic.8.Gen
JiangminTrojan.MSIL.aotqv
GoogleDetected
AviraHEUR/AGEN.1323342
Kingsoftmalware.kb.c.702
ArcabitTrojan.MSIL.Basic.8.Gen
ZoneAlarmHEUR:Trojan.MSIL.Dnoper.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VaristW32/MSIL_Kryptik.KIJ.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5484342
ALYacTrojan.MSIL.Basic.8.Gen
MAXmalware (ai score=83)
MalwarebytesBackdoor.DCRat
RisingTrojan.Dnoper!8.10CB3 (TFE:dGZlOg3hFw/p7lyDRw)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove MSIL/Spy.Agent.ETF?

MSIL/Spy.Agent.ETF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment