Spy Trojan

How to remove “TrojanSpy:MSIL/Androm!MSR”?

Malware Removal

The TrojanSpy:MSIL/Androm!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/Androm!MSR virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine TrojanSpy:MSIL/Androm!MSR?


File Info:

crc32: FC4B676A
md5: 98d9d150c0b4afc30efd34c22e176f56
name: upload_file
sha1: ba286afad44a3f4f514aff7f1dca1c159f8cbec0
sha256: c9c89543724cc2517b6f7a873f9c33cc055c237829c65a268dbdf64a21b4dd95
sha512: 8f03ca7edaebc084f20609f8005b85d8a0fc5d18187f67179b6799dd9c5c337a9584714bbafe9eedf6dbc405787b38b3fdbef723590fd16a4da7ab9b0571ca31
ssdeep: 24576:WyBtjmCojfzv3J3LTT3onKLMplOBLG6+:J72fzv3ZbT0l
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016 Badget Libraries, All Rights reserved.
Assembly Version: 1.1.0.0
InternalName: x62fx751f.exe
FileVersion: 1.1.0.0
CompanyName: Badget
LegalTrademarks:
Comments: A Library which easy advance the Functions are given for the WinForms ListView. We also add a new ListViewControl based on GlacialList.
ProductName: Badget.LibListview
ProductVersion: 1.1.0.0
FileDescription: Badget.LibListview
OriginalFilename: x62fx751f.exe

TrojanSpy:MSIL/Androm!MSR also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34612170
FireEyeTrojan.GenericKD.34612170
CAT-QuickHealBackdoor.MSIL
ALYacBackdoor.Androm.gen
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1434014
K7AntiVirusTrojan ( 0056fa411 )
BitDefenderTrojan.GenericKD.34612170
K7GWTrojan ( 005700c31 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroBackdoor.MSIL.ANDROM.THIBIBO
CyrenW32/MSIL_Kryptik.BTQ.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaTrojanSpy:MSIL/Androm.f8dcef5a
NANO-AntivirusTrojan.Win32.Androm.hygfad
ViRobotTrojan.Win32.Z.Agent.910848.AC
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareTrojan.GenericKD.34612170
EmsisoftTrojan.GenericKD.34612170 (B)
ComodoMalware@#2he6iv2pjl5y4
F-SecureTrojan.TR/BAS.Samca.bzuzi
DrWebBackDoor.SpyBotNET.25
VIPRETrojan.Win32.Generic!BT
InvinceaTroj/Kryptik-LD
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
MaxSecureTrojan.Malware.300983.susgen
SophosTroj/Kryptik-LD
IkarusTrojan.Inject
WebrootW32.Trojan.Gen
AviraTR/BAS.Samca.bzuzi
Antiy-AVLTrojan[Backdoor]/MSIL.Androm
MicrosoftTrojanSpy:MSIL/Androm!MSR
ArcabitTrojan.Generic.D21023CA
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataMSIL.Trojan.PSE.160WI0D
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Kryptik.R352345
McAfeePWS-FCRA!98D9D150C0B4
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.PNG.Generic
PandaTrj/GdSda.A
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallBackdoor.MSIL.ANDROM.THIBIBO
RisingBackdoor.Androm!8.113 (KTSE)
YandexTrojan.Igent.bUwZol.3
eGambitUnsafe.AI_Score_95%
FortinetMSIL/AgentTesla.6F56!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.ad44a3
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM03.0.39EE.Malware.Gen

How to remove TrojanSpy:MSIL/Androm!MSR?

TrojanSpy:MSIL/Androm!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment