Malware

What is “MSIL/PSW.Agent.RXB”?

Malware Removal

The MSIL/PSW.Agent.RXB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/PSW.Agent.RXB virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/PSW.Agent.RXB?


File Info:

crc32: 87B288F1
md5: 2d98e607e0a3b22cd8364dc8db989550
name: 2D98E607E0A3B22CD8364DC8DB989550.mlw
sha1: 9be77e32ed96fa69074a5e63fb0e5dd54831aa27
sha256: b81d5a21a963595ed6b0bf19c9516abe397193e0944778678faec646adfdd431
sha512: 44ca64456651859e96e66cb2b0f3c229c712d0a95522575102b699b05f27ce5c9d0b7378c13199fa671d95f5bcb532a51b9f5cfc7beafa1a8b0b3716c9f2f06e
ssdeep: 3072:eySTHiX4qI2GnNAcMzW0KUZbr5zA2yNpBH+/oDhq3:ey+HiXsNAcMzW8Zb1APBeADhq
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: mainStub.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: mainStub.exe

MSIL/PSW.Agent.RXB also known as:

K7AntiVirusPassword-Stealer ( 0056a5bb1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.PWS.StealerNET.61
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37614780
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:MSIL/RedLine.636e0f79
K7GWPassword-Stealer ( 0056a5bb1 )
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/PSW.Agent.RXB
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
BitDefenderTrojan.GenericKD.37614780
MicroWorld-eScanTrojan.GenericKD.37614780
Ad-AwareTrojan.GenericKD.37614780
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34170.jm0@a0uRBlk
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.2d98e607e0a3b22c
EmsisoftTrojan.GenericKD.37614780 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/PSW.Agent.syzgo
eGambitUnsafe.AI_Score_85%
MicrosoftPWS:MSIL/RedLine.GG!MTB
GDataMSIL.Trojan-Stealer.RedLine.A
McAfeeArtemis!2D98E607E0A3
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.RedLineStealer
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DIK21
RisingStealer.Agent!1.B723 (CLASSIC)
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.CQA!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/PSW.Agent.RXB?

MSIL/PSW.Agent.RXB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment