Malware

MSIL/PSW.Agent.STO (file analysis)

Malware Removal

The MSIL/PSW.Agent.STO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/PSW.Agent.STO virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Binary compilation timestomping detected

How to determine MSIL/PSW.Agent.STO?


File Info:

name: 1087F11ACE10F887C895.mlw
path: /opt/CAPEv2/storage/binaries/f303918c4ce0df6dd4a9bb50a3c6b44b781f4d3f779e7f371ff7e27b561929a9
crc32: F1414033
md5: 1087f11ace10f887c895a78242653f39
sha1: edc5cbcc3d7879dbf62056adbd80c7f0e16ba6c0
sha256: f303918c4ce0df6dd4a9bb50a3c6b44b781f4d3f779e7f371ff7e27b561929a9
sha512: 4f1295742a1d96d097d48555cf22c8d13be89ec498d1c10e49c33c9178521ca292258aa3d43d47f521abd329c53d77e6feb98812a4caea68b511d01500ce5dbb
ssdeep: 192:wtLQdeqb1s0rmFfFHLbRbssMGk8s1nOX/qltK:wW9GpLbRbBvs1nOvqr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17312A501B7F84614E5FF9B3428B3822186B5B9975C22CF4F1DD0518C5E36A908E92FB6
sha3_384: 00b0568c402cde131abe612d8197d5525e1469a84878d6f243a5658d037beec97a6cd381c6240f7ca811186bf5fc1de4
ep_bytes: ff250020400000000000000000000000
timestamp: 2094-05-04 00:02:37

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: start.exe
LegalCopyright:
OriginalFilename: start.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/PSW.Agent.STO also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Vibranium.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.50373973
ALYacTrojan.GenericKD.50373973
CylanceUnsafe
SangforInfostealer.MSIL.Vibranium.gen
K7AntiVirusPassword-Stealer ( 00593bbe1 )
AlibabaTrojan:MSIL/Protect.33d7c14f
K7GWPassword-Stealer ( 00593bbe1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/ABRisk.TKCB-1871
ESET-NOD32MSIL/PSW.Agent.STO
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-PSW.MSIL.Vibranium.gen
BitDefenderTrojan.GenericKD.50373973
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.50373973
EmsisoftTrojan.GenericKD.50373973 (B)
TrendMicroTROJ_GEN.R002C0PF522
McAfee-GW-EditionBehavesLike.Win32.Generic.zt
FireEyeGeneric.mg.1087f11ace10f887
SophosMal/Generic-S (PUA)
IkarusTrojan.MSIL.PSW
GDataTrojan.GenericKD.50373973
JiangminTrojan.PSW.MSIL.dvvg
AviraTR/Spy.lbjmx
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeRDN/Real Protect-PEE
VBA32TrojanPSW.MSIL.Vibranium
MalwarebytesSpyware.PasswordStealer.MSIL
TrendMicro-HouseCallTROJ_GEN.R002C0PF522
RisingTrojan.Generic/MSIL@AI.94 (RDM.MSIL:xJOx52EJNi+oh06VukVobg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.127924342.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34742.am0@aKvDnlj
AVGWin32:Trojan-gen
Cybereasonmalicious.c3d787
PandaTrj/Chgt.AB

How to remove MSIL/PSW.Agent.STO?

MSIL/PSW.Agent.STO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment