Trojan

Trojan-PSW.MSIL.Agensla.mka malicious file

Malware Removal

The Trojan-PSW.MSIL.Agensla.mka is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Agensla.mka virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Trojan-PSW.MSIL.Agensla.mka?


File Info:

name: CE1D31C18335D9AE2DEB.mlw
path: /opt/CAPEv2/storage/binaries/fa168a1bd79e5b8a7a496cad6011d8bb3ba62acd98988cb19a6e87ccd842f9df
crc32: 2DA02F20
md5: ce1d31c18335d9ae2deb46a7b8e4bd24
sha1: af45581fe57df47eaa648459d79a403aee973b52
sha256: fa168a1bd79e5b8a7a496cad6011d8bb3ba62acd98988cb19a6e87ccd842f9df
sha512: 9c7cdd5e587221ca64599d048b347baec4d5a8233553512dddf7a9674ee243e3d58b0a2c8d75d9a76a2f2be70d49189c18152c18ed78ec66ec19b97d8796a1ef
ssdeep: 768:O5DhkxKC5kgpOlLUlLSih7WL1OtNWl/96R4F2ygM:UhIB5FPhjhKLYtagRw2/M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155332A33B1E4F572CACC4AB19ED2CA940252BC365D108F0B7EC27F0F19B855954A8B27
sha3_384: 060fc9cd6d9dfd8ff79216fe33b53ffe4afb51e9c6f32e58dff8e98e84cd321a36a54599cb1a2b9b81df5ea3c85a4602
ep_bytes: 68b8134000e8f0ffffff000000000000
timestamp: 2014-08-19 11:08:38

Version Info:

Translation: 0x0409 0x04b0
ProductName: Fountain
FileVersion: 1.00
ProductVersion: 1.00
InternalName: PRON
OriginalFilename: PRON.exe

Trojan-PSW.MSIL.Agensla.mka also known as:

BkavW32.AIDetect.malware2
LionicTrojan.MSIL.Agensla.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.133
MicroWorld-eScanGen:Heur.PonyStealer.dm0@q8i@3Qoi
FireEyeGeneric.mg.ce1d31c18335d9ae
McAfeeFareit-FRM!CE1D31C18335
CylanceUnsafe
SangforTrojan.Win32.Injector.EKTR
K7AntiVirusTrojan ( 005616161 )
AlibabaTrojan:Win32/Wacatac.269
K7GWTrojan ( 005616161 )
Cybereasonmalicious.18335d
BitDefenderThetaGen:NN.ZevbaCO.34182.dm0@a8i@3Qoi
VirITTrojan.Win32.VBZenPack_Heur
CyrenW32/Kryptik.BDY.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EKTR
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SME.hp
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-PSW.MSIL.Agensla.mka
BitDefenderGen:Heur.PonyStealer.dm0@q8i@3Qoi
NANO-AntivirusTrojan.Win32.Agensla.hphxuh
AvastWin32:Trojan-gen
TencentMsil.Trojan-qqpass.Qqrob.Szbp
EmsisoftGen:Heur.PonyStealer.dm0@q8i@3Qoi (B)
ComodoMalware@#1aof9iudpdzf7
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.FAREIT.SME.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.qt
SophosMal/Generic-R + Mal/FareitVB-AB
IkarusTrojan.VB.Crypt
AviraHEUR/AGEN.1107767
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.30C6D90
GridinsoftRansom.Win32.Wacatac.sa
GDataGen:Heur.PonyStealer.dm0@q8i@3Qoi
AhnLab-V3Trojan/Win32.Fareit.C4018058
ALYacGen:Heur.PonyStealer.dm0@q8i@3Qoi
MalwarebytesTrojan.MalPack.VB
APEXMalicious
RisingDownloader.Guloader!1.C589 (CLOUD)
YandexTrojan.Igent.bUmZu5.8
SentinelOneStatic AI – Suspicious PE
FortinetW32/GenKryptik.EFHR!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-PSW.MSIL.Agensla.mka?

Trojan-PSW.MSIL.Agensla.mka removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment