Malware

MSIL/PSW.Agent.SIX removal

Malware Removal

The MSIL/PSW.Agent.SIX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/PSW.Agent.SIX virus can do?

  • Dynamic (imported) function loading detected
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/PSW.Agent.SIX?


File Info:

name: 3855CABB02A00B13E7F2.mlw
path: /opt/CAPEv2/storage/binaries/15730ea2e9f52a6fe98176438aabd29c1d7a0feed587e79565e2dc9643fa7528
crc32: CFD8C0AF
md5: 3855cabb02a00b13e7f2cdc697ce0e27
sha1: 832e3e3e31497a3115d96132a161712c85be1511
sha256: 15730ea2e9f52a6fe98176438aabd29c1d7a0feed587e79565e2dc9643fa7528
sha512: 621ccc083d6053497c20b5215159b654a48c37d82bda3125761752649ca2e030c99aa18a8734e26d8a20ac8f101b4b4596047d9dc46c4475aa501e0cdc7074fa
ssdeep: 768:zpFAX0SQTwOY5Opfcq5yFuAHpPqqPVa75/U/Rt3t6h4dVsB9ks2r0Ek7kqRgjD:zpFA5cEoqs75qPJVQer0HnQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE33D0085EEEC523CADE87BC094B978017E692AB8401DBEF7D9421D40E477921067F6F
sha3_384: bc4d2765806b3bdc395039d7dcb13d85b9803acbe95a55c0625de2c8c0bb46f25a31d06d01780c3e93640a83aa9fa1b4
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-11 08:48:12

Version Info:

Translation: 0x0000 0x04b0
Comments: https://github.com/L1ghtM4n/DynamicStealer
CompanyName:
FileDescription: DynamicStealer
FileVersion: 1.0.0.0
InternalName: DynamicDll.exe
LegalCopyright: Copyright © LightMan 2020
LegalTrademarks:
OriginalFilename: DynamicDll.exe
ProductName: DynamicDll
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/PSW.Agent.SIX also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38253349
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeArtemis!3855CABB02A0
CylanceUnsafe
AlibabaTrojan:MSIL/Generic.5a287316
Cybereasonmalicious.e31497
BitDefenderThetaGen:NN.ZemsilF.34084.dm0@aWK8fxj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Agent.SIX
TrendMicro-HouseCallTROJ_GEN.R002H0DLB21
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Stealer.xtv
BitDefenderTrojan.GenericKD.38253349
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.38253349
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.3855cabb02a00b13
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.I7RHJP
eGambitUnsafe.AI_Score_100%
MAXmalware (ai score=81)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Agensla.R426922
MalwarebytesSpyware.DynamicStealer
APEXMalicious
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.SIX!tr.pws
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove MSIL/PSW.Agent.SIX?

MSIL/PSW.Agent.SIX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment