Spy

How to remove “Spyware:MSIL/Stealer!mclg”?

Malware Removal

The Spyware:MSIL/Stealer!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware:MSIL/Stealer!mclg virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script process created a new process
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Spyware:MSIL/Stealer!mclg?


File Info:

name: 0F4A058DF110721AE1C3.mlw
path: /opt/CAPEv2/storage/binaries/b0f37414ed4c212b1198e06390ae4bcafba5e0e2b7282f1a9544465c662a4675
crc32: F163F1CD
md5: 0f4a058df110721ae1c37bd040dd00ef
sha1: 26b65700338ca96c33ccb151f69109784c9dcaf4
sha256: b0f37414ed4c212b1198e06390ae4bcafba5e0e2b7282f1a9544465c662a4675
sha512: 7c679e097d3de3f6589ab7b124590b77ff58926fb4567ec699482f4169ab58614a7d4bf00ebeca1558f3e17a44945d41e284548916168d9cb8e507791d156338
ssdeep: 49152:UbA30Z6DaqYLSU6gWhWjeluCo6xJUxm5CMzD:UbV6DceU6gW0jeJCAD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17ED5DF02BAC5C911D06A1637C5EF842447BCBE413B62EB1A7EAE336D65213A75D0D2CF
sha3_384: 15eaeb2316dcb6ef54a149f604dc4f46eef035fc80efa5ba32849ed9acb1b7ca57a69dd188fb9b49e467605fabb289a9
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

Spyware:MSIL/Stealer!mclg also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Makop.trQA
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Uztuby.19
FireEyeGeneric.mg.0f4a058df110721a
ALYacIL:Trojan.MSILZilla.9872
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056e5201 )
AlibabaTrojanSpy:MSIL/Stealer.d8098cb4
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.df1107
BitDefenderThetaGen:NN.ZemsilF.34212.Bs0@aaDbLAni
CyrenW32/MSIL_Agent.LQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002H0CAV22
AvastWin32:RATX-gen [Trj]
ClamAVWin.Trojan.Uztuby-9855059-0
KasperskyUDS:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.Uztuby.19
ViRobotTrojan.Win32.Z.Uztuby.2859825
Ad-AwareIL:Trojan.MSILZilla.9872
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftTrojan.Uztuby.19 (B)
Paloaltogeneric.ml
GDataWin32.Trojan.BSE.1CL7UZW
AviraHEUR/AGEN.1203070
Antiy-AVLTrojan/Generic.ASMalwS.351C732
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Uztuby.19
MicrosoftSpyware:MSIL/Stealer!mclg
CynetMalicious (score: 100)
McAfeeArtemis!0F4A058DF110
MAXmalware (ai score=82)
VBA32TrojanSpy.MSIL.Stealer
MalwarebytesSpyware.PasswordStealer
APEXMalicious
RisingTrojan.Generic/MSIL@AI.97 (RDM.MSIL:l8trtxQBahnoqT54Ja5J5Q)
SentinelOneStatic AI – Malicious SFX
eGambitGeneric.Malware
FortinetMSIL/Agent.DEK!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/CI.A

How to remove Spyware:MSIL/Stealer!mclg?

Spyware:MSIL/Stealer!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment