Trojan

Trojan:MSIL/Fanny removal guide

Malware Removal

The Trojan:MSIL/Fanny is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Fanny virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan:MSIL/Fanny?


File Info:

name: 33E7EA62012E608F84C2.mlw
path: /opt/CAPEv2/storage/binaries/c182b310447d0b95dea3502625e976613efc45c14abb3889df048302d2226e87
crc32: 78168BD3
md5: 33e7ea62012e608f84c28f17e815f538
sha1: 47b16cd43815d2d793340381fa078ea3354403ed
sha256: c182b310447d0b95dea3502625e976613efc45c14abb3889df048302d2226e87
sha512: cd1d183c3b27951c023b487647784d63c87b25d8cdd0a8183be01ad634e6d945798591ac2b97cc8de0e0cfaae2c0d1a3a0d517987832ad8dc53ae1623525b4d6
ssdeep: 96:rYqYmEMnzUfIkexMUf3Ecm/5K5pHBXzifz5br8DNsHdaLK:rhYtxfIBx45K3HB+zuDq9j
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FFE1C55A7BEC0A2AE8AF5B781A73131197B2FD025A33D79F4CD4016909327641619FE1
sha3_384: 3838d4a4963be27ebcefd8c976f4ab569e889ef213a795380a99ffb7f016d602266ce4d508f2b0f926c9f80ef71a7fb3
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-01-17 17:47:05

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: nbjqljwm.dll
LegalCopyright:
OriginalFilename: nbjqljwm.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan:MSIL/Fanny also known as:

BkavW32.AIDetectMalware.CS
MicroWorld-eScanGen:Variant.Bulz.599033
FireEyeGeneric.mg.33e7ea62012e608f
SkyhighTrojan-FTTC!33E7EA62012E
McAfeeGenericRXKZ-AA!33E7EA62012E
MalwarebytesTrojan.MalPack.MSIL
VIPREGen:Variant.Bulz.599033
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00569f861 )
BitDefenderGen:Variant.Bulz.599033
K7GWTrojan ( 00569f861 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.UJ
APEXMalicious
TrendMicro-HouseCallTrojan.MSIL.LEMONDUCK.SM
AvastWin32:WormX-gen [Wrm]
ClamAVWin.Packed.Ursu-9757277-0
KasperskyHEUR:Worm.MSIL.Agent.gen
AlibabaWorm:MSIL/Fanny.32321eef
TencentWorm.Msil.Agent.fa
EmsisoftGen:Variant.Bulz.599033 (B)
GoogleDetected
F-SecureHeuristic.HEUR/AGEN.1300930
DrWebWin32.HLLW.UsbmonNET.1
ZillyaWorm.Agent.Win32.61396
TrendMicroTrojan.MSIL.LEMONDUCK.SM
SophosTroj/MSIL-PNL
SentinelOneStatic AI – Malicious PE
VaristW32/Trojan.FBM.gen!Eldorado
AviraHEUR/AGEN.1300930
MAXmalware (ai score=85)
Antiy-AVLWorm/MSIL.Agent
MicrosoftTrojan:MSIL/Fanny
XcitiumMalware@#1p7urmofri4nh
ArcabitTrojan.Bulz.D923F9
ZoneAlarmHEUR:Worm.MSIL.Agent.gen
GDataMSIL.Trojan.Fanny.A
AhnLab-V3Malware/Win.Generic.R419340
ALYacGen:Variant.Bulz.599033
TACHYONTrojan/W32.DN-Agent.7168.AG
VBA32Worm.MSIL.Usbmon.Heur
Cylanceunsafe
RisingTrojan.DTLMiner!1.DB4F (CLASSIC)
YandexWorm.Agent!r9yo/InYbzs
IkarusWorm.MSIL.Agent
MaxSecureWorm.WIN32.MSIL.Agent.gen.010221
FortinetMSIL/Agent.UJ!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
alibabacloudTrojan:MSIL/Cridex

How to remove Trojan:MSIL/Fanny?

Trojan:MSIL/Fanny removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment