Trojan

How to remove “Trojan:MSIL/Fanny”?

Malware Removal

The Trojan:MSIL/Fanny is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Fanny virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan:MSIL/Fanny?


File Info:

name: E07AF77DEAC79FA1C34B.mlw
path: /opt/CAPEv2/storage/binaries/33ebd575fe75bfd32fc0b1084a52f0cb026e7fb51bb7665a817a7dbcceb73615
crc32: B08933F2
md5: e07af77deac79fa1c34bc1431ad8440f
sha1: 9fdd367c74635fbae424ef0eb317e617735da0cb
sha256: 33ebd575fe75bfd32fc0b1084a52f0cb026e7fb51bb7665a817a7dbcceb73615
sha512: 5bff398af3388cc5bbdebf4f944e288d9e5de4ddbf2d24a8a6951432d00eb3483c929153a834b6bb0f0b49c77406a890dd7f9d83125c50757de1f3bc0588410f
ssdeep: 96:AqYmEMnzUfIkexMUf3Ecm/5K5cHsXzifz58l8DN+HAoK:pYtxfIBx45KqHs+zlD8q
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T157E1D75A7BD80A26E8EF4F781AB313119772FD035A33D79F4CC4116909327285629FE4
sha3_384: 377ecc6fa00b993237d8302ea33f5995de0a2a3e73569e13d5e4c37479b71efbbc472e79423ee4fecd9d34c1107e8a63
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-01-13 22:05:33

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: 9252qbi4.dll
LegalCopyright:
OriginalFilename: 9252qbi4.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan:MSIL/Fanny also known as:

BkavW32.AIDetectMalware.CS
LionicWorm.MSIL.Agent.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.599033
FireEyeGeneric.mg.e07af77deac79fa1
SkyhighTrojan-FTTC!E07AF77DEAC7
ALYacGen:Variant.Bulz.599033
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:MSIL/Fanny.7a930fe5
K7GWTrojan ( 00569f861 )
K7AntiVirusTrojan ( 00569f861 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Agent.UJ
APEXMalicious
ClamAVWin.Packed.Ursu-9757277-0
KasperskyHEUR:Worm.MSIL.Agent.gen
BitDefenderGen:Variant.Bulz.599033
AvastWin32:WormX-gen [Wrm]
TencentWorm.Msil.Agent.fa
TACHYONTrojan/W32.DN-Agent.7168.AG
EmsisoftGen:Variant.Bulz.599033 (B)
F-SecureHeuristic.HEUR/AGEN.1300930
DrWebWin32.HLLW.UsbmonNET.1
VIPREGen:Variant.Bulz.599033
TrendMicroTrojan.MSIL.LEMONDUCK.SM
SophosTroj/MSIL-PNL
IkarusWorm.MSIL.Agent
GDataMSIL.Trojan.Fanny.A
JiangminWorm.MSIL.gtq
VaristW32/Trojan.FBM.gen!Eldorado
AviraHEUR/AGEN.1300930
XcitiumMalware@#jo4srtbi19fn
ArcabitTrojan.Bulz.D923F9
ZoneAlarmHEUR:Worm.MSIL.Agent.gen
MicrosoftTrojan:MSIL/Fanny
GoogleDetected
AhnLab-V3Malware/Win.Generic.R419340
McAfeeGenericRXKZ-AA!E07AF77DEAC7
MAXmalware (ai score=87)
VBA32Worm.MSIL.Usbmon.Heur
MalwarebytesTrojan.MalPack.MSIL
TrendMicro-HouseCallTrojan.MSIL.LEMONDUCK.SM
RisingTrojan.DTLMiner!1.DB4F (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.WIN32.MSIL.Agent.gen.010221
FortinetMSIL/Agent.UJ!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Fanny?

Trojan:MSIL/Fanny removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment