Spy Trojan

Trojan-Spy.MSIL.Agent.acui (file analysis)

Malware Removal

The Trojan-Spy.MSIL.Agent.acui is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.MSIL.Agent.acui virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan-Spy.MSIL.Agent.acui?


File Info:

name: 08331F185B0A19A7BD64.mlw
path: /opt/CAPEv2/storage/binaries/736dcec42e5ef796e3a3169ad2a1a3be19de7a1c57e6aa8db962bffbcdf3cd28
crc32: 8E970C18
md5: 08331f185b0a19a7bd64ff5fe3554acc
sha1: de680b959146d003c3b62c304f3aa7509188f994
sha256: 736dcec42e5ef796e3a3169ad2a1a3be19de7a1c57e6aa8db962bffbcdf3cd28
sha512: b63ddabc824e42455137375a9882d923acbede9944de76834508e92742ddc3353b92c86fb0a8e806eacce37bc6377c1254dbed6332355c902335727b08478ca1
ssdeep: 6144:QOw1XxWITpjoNij9T1Pzb2u/d6AjWcPyC4koXAXUd2CCkm/taEFl3g6RswD1f6Wt:Fwhb2u/d6AjWcfHEhm/XFl3fRRUWP
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14F84E11173D28972E2AB053655B09B319BBCFC3256B2CF5F138C12299F252C09B657BB
sha3_384: 8956801b73b86b51c2b32d357e9da1e6dbab0b65e9004bf2036b2d9f442cb10b3c1484aeae0f95fb97c5b8de41d7cfe3
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-10-04 16:47:18

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.1.0.76
InternalName: ThorVariant.exe
LegalCopyright:
OriginalFilename: ThorVariant.exe
ProductVersion: 1.1.0.76
Assembly Version: 1.1.0.76

Trojan-Spy.MSIL.Agent.acui also known as:

LionicTrojan.MSIL.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.48244
MicroWorld-eScanApplication.RanSim.D
FireEyeGeneric.mg.08331f185b0a19a7
McAfeeGenericRXGR-FH!08331F185B0A
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1030455
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005159961 )
AlibabaTrojanSpy:Win32/Fasem.fbc0c997
K7GWTrojan ( 005159961 )
Cybereasonmalicious.85b0a1
BitDefenderThetaGen:NN.ZemsilF.34114.xm0@auU9Kbh
CyrenW32/S-704b571d!Eldorado
SymantecHacktool.Cryptran!g2
ESET-NOD32a variant of MSIL/Riskware.KnownBe4.A
TrendMicro-HouseCallTROJ_GEN.R002C0OA822
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-6268112-0
KasperskyTrojan-Spy.MSIL.Agent.acui
BitDefenderApplication.RanSim.D
NANO-AntivirusTrojan.Win32.Drop.ezgabu
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Fasem.ya
Ad-AwareApplication.RanSim.D
EmsisoftTrojan.Ransom (A)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OA822
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosGeneric PUA NO (PUA)
SentinelOneStatic AI – Malicious PE
GDataApplication.RanSim.D
JiangminTrojan.Generic.blxog
AviraHEUR/AGEN.1127299
MAXmalware (ai score=72)
Antiy-AVLTrojan/Generic.ASMalwS.22AD570
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Occamy.C73
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dynamer.R218064
ALYacApplication.RanSim.D
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.2597817002
APEXMalicious
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL:uddM/PkD7iiiMae/uT78nw)
YandexTrojan.Miner!eEtg0HligBo
IkarusTrojan.Win32.Dynamer
FortinetMSIL/Fasem.A!tr.ransom
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan-Spy.MSIL.Agent.acui?

Trojan-Spy.MSIL.Agent.acui removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment