Malware

MSIL/PSW.Agent.SZC removal guide

Malware Removal

The MSIL/PSW.Agent.SZC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/PSW.Agent.SZC virus can do?

  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/PSW.Agent.SZC?


File Info:

name: 969DCCCF9578D4E634BD.mlw
path: /opt/CAPEv2/storage/binaries/a4c1421567878180b905aeccca79f7979c87d93f4c8b94b615d90b724104823a
crc32: E0F8031A
md5: 969dcccf9578d4e634bd5d28fa673e28
sha1: 0f4513eaa7930789331e7ed13d0210f820db128a
sha256: a4c1421567878180b905aeccca79f7979c87d93f4c8b94b615d90b724104823a
sha512: 9f781f28e5d5db386d863603749e22761346218310203282310764eaf29b5ee93faa5b1645be349c961ee6f435eb498d736b2cf09d01aa1537c6c73fa614fb89
ssdeep: 6144:lloZM3fsXtioRkts/cnnK6cMlPpUiAfboaxUyzzqBapswp8e1mqi:noZ1tlRk83MlPpUiAfboaxUyzzq0pJY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3345A5837B88F12E25F8BBEE5B1549F8771F103E90AF7CE0C8895EC2411B42E949A57
sha3_384: 5d2d3875bd96befbd41b97c77d0e9ab19e4679a60264725c923907408818ff6b078be3b67e433c81b1bf91fd392da020
ep_bytes: ff250020400000000000000000000000
timestamp: 2053-02-19 18:54:36

Version Info:

Translation: 0x0000 0x04b0
Comments: Payload for Umbral Stealer
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/PSW.Agent.SZC also known as:

LionicTrojan.Win32.Dizemp.4!c
DrWebTrojan.PWS.Stealer.36948
MicroWorld-eScanIL:Trojan.MSILZilla.27419
ClamAVWin.Packed.Msilzilla-9952790-0
FireEyeGeneric.mg.969dcccf9578d4e6
ALYacIL:Trojan.MSILZilla.27419
Cylanceunsafe
ZillyaTrojan.Dizemp.Win32.479
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 005a3e671 )
AlibabaTrojan:MSIL/Dizemp.5f654860
K7GWPassword-Stealer ( 005a3e671 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36318.om0@aOsDFAk
CyrenW32/MSIL_Agent.FGE.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/PSW.Agent.SZC
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Dizemp.gen
BitDefenderIL:Trojan.MSILZilla.27419
TencentMalware.Win32.Gencirc.13d1acb1
EmsisoftIL:Trojan.MSILZilla.27419 (B)
F-SecureHeuristic.HEUR/AGEN.1307507
VIPREIL:Trojan.MSILZilla.27419
TrendMicroTROJ_GEN.R002C0XFE23
McAfee-GW-EditionGenericRXWC-QA!969DCCCF9578
SophosTroj/Umbral-A
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILZilla.27419
JiangminTrojan.MSIL.aoobx
AviraHEUR/AGEN.1307507
MAXmalware (ai score=100)
Antiy-AVLTrojan/MSIL.Dizemp
ArcabitIL:Trojan.MSILZilla.D6B1B
ZoneAlarmHEUR:Trojan.MSIL.Dizemp.gen
MicrosoftTrojan:MSIL/FormBook.CD!MTB
GoogleDetected
AhnLab-V3Trojan/Win.MSILZilla.C5437246
McAfeeGenericRXWC-QA!969DCCCF9578
DeepInstinctMALICIOUS
VBA32TScope.Trojan.MSIL
MalwarebytesPasswordStealer.Spyware.Stealer.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0XFE23
RisingStealer.Agent!8.C2 (CLOUD)
YandexTrojan.PWS.Agent!ctIzRdhYH8A
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.100993507.susgen
FortinetMSIL/Agent.SZC!tr.pws
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]

How to remove MSIL/PSW.Agent.SZC?

MSIL/PSW.Agent.SZC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment