Trojan

About “Trojan-PSW.MSIL.Agensla.gwq” infection

Malware Removal

The Trojan-PSW.MSIL.Agensla.gwq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Agensla.gwq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Urdu (Pakistan)
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-PSW.MSIL.Agensla.gwq?


File Info:

crc32: 7DF70AEC
md5: 8736d9c53902a45c16cd6cacdea628c4
name: win.exe
sha1: df779b6229e108ef490b9eb48b87dfb9f3a8adb3
sha256: fc4bc043d438967115a50571e55484e01023e03d975d646ca345e948092f17b0
sha512: db2cef94186de523ad59a502694499cf15e6ca9a5b1c99a7b5ade51eac11d49779a09b97c391a04e7b8dfeaf33713e2f5ca2e89199aad9f6c8448a53ac934a46
ssdeep: 24576:02QiV15IYI4CEwj1xidegbYzxYx6rv7K:02QiV15IYI4CEwj1xidVIL/K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
ProductVersion: 1.00
InternalName: Property
FileVersion: 1.00
OriginalFilename: Property.exe
ProductName: Doea

Trojan-PSW.MSIL.Agensla.gwq also known as:

MicroWorld-eScanTrojan.GenericKD.42069946
FireEyeGeneric.mg.8736d9c53902a45c
McAfeeArtemis!8736D9C53902
ALYacTrojan.GenericKD.42070117
MalwarebytesTrojan.MalPack.VB
VIPREBackdoor.VB.Tofsee.f (v)
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42069946
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.229e10
Invinceaheuristic
BitDefenderThetaGen:NN.ZevbaF.32515.cn0@amqhAPdH
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EJGJ
GDataTrojan.GenericKD.42069946
KasperskyTrojan-PSW.MSIL.Agensla.gwq
RisingTrojan.Injector!1.B459 (CLASSIC)
Endgamemalicious (high confidence)
DrWebTrojan.PWS.Stealer.17385
McAfee-GW-EditionBehavesLike.Win32.VBObfus.th
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.HCBP-4083
WebrootW32.Trojan.Gen
ArcabitTrojan.Generic.D281EFBA
AhnLab-V3Win-Trojan/VBKrand.Gen
ZoneAlarmTrojan-PSW.MSIL.Agensla.gwq
MicrosoftTrojan:Win32/Tiggre!plock
Acronissuspicious
MAXmalware (ai score=87)
Ad-AwareTrojan.GenericKD.42069946
CylanceUnsafe
IkarusWin32.Outbreak
FortinetMalicious_Behavior.SB
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-PSW.MSIL.Agensla.gwq?

Trojan-PSW.MSIL.Agensla.gwq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment