Trojan

Trojan.Agent.CSPL information

Malware Removal

The Trojan.Agent.CSPL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CSPL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.CSPL?


File Info:

name: 0B47CF03417BFCF1BF2E.mlw
path: /opt/CAPEv2/storage/binaries/2888c3efa003633d813816833a898e59cc6b71dfd5fd541de693e485c3e5b965
crc32: 1FF2B95C
md5: 0b47cf03417bfcf1bf2e384264ffbb43
sha1: 41862ab09f021642f8a28876afdcc6cebed2f941
sha256: 2888c3efa003633d813816833a898e59cc6b71dfd5fd541de693e485c3e5b965
sha512: 38696aecd22ecf00b0a4f1e83bce8cf88a9f417c90770fbe5e8b9aa8398a3eed79c94ae1f5dc25db0ef08efa9a8f1cc1be509d9e0f90e35de24e8a5467855613
ssdeep: 24576:iBUyG/S8ep10lyrHgBH+EgSBbIWBrwhr:zyXnuyrHMH+xSFI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D675122FB1C5E53BCC0288B32F64C5F56A555C020A73ED63A78D3B2E4A790669B2CD5C
sha3_384: 6f3d9180e2e938dba107cc1a5a39dae42509dfff7c76f520aa212204695fd713c08a5f81af15e916c430454ff55368eb
ep_bytes: e890030000e98efeffff558bec6a00ff
timestamp: 2017-12-29 10:42:24

Version Info:

0: [No Data]

Trojan.Agent.CSPL also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CSPL
FireEyeGeneric.mg.0b47cf03417bfcf1
CAT-QuickHealSoftwareBundler.Prepscram.C7
SkyhighBehavesLike.Win32.Generic.tm
ALYacTrojan.Agent.CSPL
Cylanceunsafe
ZillyaAdware.Generic.Win32.45820
SangforSuspicious.Win32.Save.a
AlibabaAdWare:Win32/StartSurf.a52182e7
K7GWTrojan ( 0052269b1 )
K7AntiVirusTrojan ( 0052269b1 )
BitDefenderThetaGen:NN.ZexaF.36802.HzW@aa9swnbk
VirITTrojan.Win32.Vittalia.UQJ
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.FWQG
APEXMalicious
AvastWin32:Evo-gen [Trj]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderTrojan.Agent.CSPL
NANO-AntivirusTrojan.Win32.Vittalia.ewpasd
TencentMalware.Win32.Gencirc.10b24933
EmsisoftTrojan.Agent.CSPL (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Vittalia.13945
VIPRETrojan.Agent.CSPL
TrendMicroTROJ_GEN.R002C0PB524
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
MAXmalware (ai score=98)
JiangminAdWare.StartSurf.akq
WebrootW32.Malware.gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/S-5c8c533d!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.AGeneric
KingsoftWin32.HeurC.KVMH008.a
MicrosoftSoftwareBundler:Win32/Prepscram
XcitiumApplication.Win32.IStartSurf.BS@7lng48
ArcabitTrojan.Agent.CSPL
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataTrojan.Agent.CSPL
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.StartSurf.R217036
Acronissuspicious
McAfeePacked-WG!0B47CF03417B
TACHYONTrojan/W32.Agent.1601024.PB
VBA32BScope.Trojan.Vittalia
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PB524
RisingTrojan.Kryptik!1.B07C (CLASSIC)
YandexTrojan.GenAsa!narcCW5FimA
IkarusPUA.Win32.Prepscram
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FWQG!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudAdWare:Win/Generic

How to remove Trojan.Agent.CSPL?

Trojan.Agent.CSPL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment