Spy Trojan

Trojan-Spy.MSIL.Stealer.ayz removal guide

Malware Removal

The Trojan-Spy.MSIL.Stealer.ayz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.MSIL.Stealer.ayz virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Spy.MSIL.Stealer.ayz?


File Info:

crc32: AE5E40A2
md5: 3d0142d050e3f4959de52ee5e32512a0
name: 3D0142D050E3F4959DE52EE5E32512A0.mlw
sha1: e09836ed6d7140c23aa0d45d2925e61ebdccfe69
sha256: 95c7436558a5834379102b569f796d288fa04d8cbc52d7719709caec3cc7da09
sha512: e753d709a5c5c5ac1fa31bbfa5373db6954211934a44453cf6afb95dba32ee444c9cf913c2045d67f473dd31054414f4a63cd8efc39b8c64b23e0556485ea8e5
ssdeep: 12288:0Qnk3GDYKGcblwtX+t4Y8XA5SSJhJhnXUV5c9CxNsXZ:IAOcZwXYCA5SUpkV5BNsp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Spy.MSIL.Stealer.ayz also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45807160
CAT-QuickHealTrojan.Phonzy
McAfeeRDN/Generic.dx
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00569e9c1 )
BitDefenderTrojan.GenericKD.45807160
K7GWTrojan ( 00569e9c1 )
Cybereasonmalicious.050e3f
CyrenW32/Downloader.UK.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32BAT/Runner.EG
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Uztuby-9837457-0
KasperskyTrojan-Spy.MSIL.Stealer.ayz
AlibabaTrojan:BAT/Runner.d585b62e
Ad-AwareTrojan.GenericKD.45807160
EmsisoftTrojan.GenericKD.45807160 (B)
ComodoMalware@#2e4uvz3iq1qfy
F-SecureTrojan.TR/Runner.pubrg
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.3d0142d050e3f495
SophosMal/Generic-R + Mal/RarMal-R
IkarusTrojan.Rasftuby
MaxSecureWin.MxResIcn.Heur.Gen
AviraTR/Runner.pubrg
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Script/Phonzy.A!ml
GridinsoftTrojan.Win32.Downloader.sa
ArcabitTrojan.Generic.D2BAF638
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AhnLab-V3Malware/Win32.Generic.C4349242
ZoneAlarmTrojan-Spy.MSIL.Stealer.ayz
GDataTrojan.GenericKD.45807160
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.45807160
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CBQ21
MAXmalware (ai score=84)
FortinetW32/Uztuby.17!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Backdoor.Uztuby.HwYDjR8A

How to remove Trojan-Spy.MSIL.Stealer.ayz?

Trojan-Spy.MSIL.Stealer.ayz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment