Trojan

What is “MSIL/TrojanClicker.Agent.NXM”?

Malware Removal

The MSIL/TrojanClicker.Agent.NXM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanClicker.Agent.NXM virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine MSIL/TrojanClicker.Agent.NXM?


File Info:

name: 783AFAFA7034733F6390.mlw
path: /opt/CAPEv2/storage/binaries/bb75e36e6d2f504444fb4cf31c5086a4780775c10bc165ebcf19c66ea8c71196
crc32: 4AC7918C
md5: 783afafa7034733f63901acbac0b4d13
sha1: 3e1dcb2cce48e86a6d5fe1c80c8551fa4d498cce
sha256: bb75e36e6d2f504444fb4cf31c5086a4780775c10bc165ebcf19c66ea8c71196
sha512: 9eb91239ed54e50ab4b253d609015ecbda22488027222ab729c6e33a62b3c4f867d95229bf7edd72038c47aae79ab3fe68bc535d86793e5ca966bf19a20b6987
ssdeep: 196608:Z+YHJHx1OmP9YCc/XJTdR3vJ085k/QsTO+s3exaud57BBTTC/Zy4vvVc8zz0HBq2:Z+YHDwo9hc/XJ7ftFsid3esoTC/f1jve
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140B633529D090AC3D2A770784C25CBB3E853EF8E1254665E24C37D3629F725E1B872BB
sha3_384: d8ebd3173b39031baf27ecb605ce4bd980821367fbb55efd0186c50102ebeb776c51df43154da0721c7a90ffbfabb90a
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:53:44

Version Info:

0: [No Data]

MSIL/TrojanClicker.Agent.NXM also known as:

BkavW32.Common.7B890C9F
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.783afafa7034733f
SkyhighBehavesLike.Win32.Generic.vc
McAfeeArtemis!B146B54F69E9
Cylanceunsafe
SangforTrojan.Win32.Clicker.Vlia
K7AntiVirusTrojan ( 005b0a511 )
AlibabaTrojan:Win32/Fsysna.6f53de5c
K7GWTrojan ( 005b0a511 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanClicker.Agent.NXM
AvastNSIS:MalwareX-gen [Trj]
ClamAVWin.Trojan.Sodinokibi-9946701-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.71856152
RisingTrojan.Clicker!8.1972 (CLOUD)
EmsisoftTrojan.GenericKD.71856152 (B)
GoogleDetected
F-SecureTrojan.TR/Clicker.mzlxa
VIPRETrojan.GenericKD.71856152
SophosMal/Generic-S
IkarusTrojan-Dropper.NSIS.Agent
AviraTR/Clicker.thkmo
MAXmalware (ai score=88)
Antiy-AVLTrojan[Clicker]/MSIL.Agent
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojan:Win32/Vigorf.A
ArcabitTrojan.Generic.D4487018 [many]
ZoneAlarmHEUR:Trojan.Win32.Fsysna.gen
GDataWin32.Trojan.Agent.C53C48
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.71856152
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TencentWin32.Adware.Runner.Osmw
FortinetAdware/TrojanClicker_Agent
AVGNSIS:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove MSIL/TrojanClicker.Agent.NXM?

MSIL/TrojanClicker.Agent.NXM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment