Trojan

Trojan-PSW.MSIL.Agensla.jjp (file analysis)

Malware Removal

The Trojan-PSW.MSIL.Agensla.jjp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Agensla.jjp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-PSW.MSIL.Agensla.jjp?


File Info:

crc32: 71FDB0F0
md5: 90b29797d49f4bec1ab0871e3cd4e7a1
name: client.exe
sha1: 17bd24ad4ad41312c72d638a2a4f117b93e03f6b
sha256: 193b380bba0b9346151e1d0f658a7ed1ab703aa0e0ab9ac3fd2a1022044f69fc
sha512: 71ad1f3ad106b2743a68d15a5da1e27d1742d73fdecf85f09e2e8b1580c4a476da5f0f8f552bfcc31e1c3fcf1fea0c6a91ba550a749322027a9455ddc5aeb8b7
ssdeep: 49152:iu0c++OCvkGs9FaMVZa2CxAvYApKf5vzvcrfCukj2Y:tB3vkJ9I2CxApKfBvcrfC32
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-PSW.MSIL.Agensla.jjp also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.AutoIT.Agent.AAJ
FireEyeGeneric.mg.90b29797d49f4bec
ALYacTrojan.Agent.Wacatac
CylanceUnsafe
K7AntiVirusTrojan ( 0055ee981 )
BitDefenderTrojan.GenericKD.32964595
K7GWTrojan ( 0055ee981 )
Cybereasonmalicious.d4ad41
Invinceaheuristic
SymantecPacked.Generic.548
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.MSIL.Agensla.jjp
AlibabaTrojan:Win32/autoit.ali2000008
AegisLabTrojan.Win32.AutoIT.4!c
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
Ad-AwareTrojan.GenericKD.32964595
F-SecureTrojan.TR/Autoit.pmxkf
DrWebTrojan.Inject3.33272
TrendMicroTrojan.Win32.WACATAC.THABOBO
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.32964595 (B)
GDataTrojan.GenericKD.32964595
AviraTR/Autoit.pmxkf
MicrosoftTrojan:Win32/Wacatac.C!ml
Endgamemalicious (high confidence)
ZoneAlarmTrojan-PSW.MSIL.Agensla.jjp
McAfeeArtemis!90B29797D49F
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.AutoIt
ESET-NOD32a variant of Win32/Injector.Autoit.EWZ
TrendMicro-HouseCallTrojan.Win32.WACATAC.THABOBO
TencentMsil.Trojan-qqpass.Qqrob.Hsry
IkarusTrojan-Spy.Keylogger.AgentTesla
FortinetAutoIt/Injector.ESJ!tr
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.PSW.b65

How to remove Trojan-PSW.MSIL.Agensla.jjp?

Trojan-PSW.MSIL.Agensla.jjp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment