Trojan

Trojan-PSW.MSIL.Agensla.nkf (file analysis)

Malware Removal

The Trojan-PSW.MSIL.Agensla.nkf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Agensla.nkf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-PSW.MSIL.Agensla.nkf?


File Info:

crc32: DD0F643F
md5: 69d6e48a969c8d474c27d396e2be51a5
name: new-crypttttttt.exe
sha1: 462589ab26d54d6973b20be4ce7051290ae4c01e
sha256: aa86f9e43feac4a0af654ab00ec2368136d35d4c2b79c5b82434e806e3e945ad
sha512: e9296cbafb954e04fe0b581e46f6d7dd3ebee15e57f69982da85de11b9cbd45101a656fb9319a31970ae4c5cecfe0604adb444ff5fc3bbf050b243ac38dba97f
ssdeep: 24576:2tb20pkaCqT5TBWgNQ7aNQEJ4UfR6qtczlqnyUP6Cy+CBTusCy7PVTXuPZXgOIb:jVg5tQ7aNnCUbtyqnyVB/CIPxXkH+H5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-PSW.MSIL.Agensla.nkf also known as:

MicroWorld-eScanTrojan.GenericKD.33536266
Qihoo-360Generic/HEUR/QVM10.2.D291.Malware.Gen
McAfeeArtemis!69D6E48A969C
CylanceUnsafe
AegisLabTrojan.Win32.DarkKomet.mf0o
SangforMalware
K7AntiVirusTrojan ( 005621461 )
BitDefenderTrojan.GenericKD.33536266
K7GWTrojan ( 005621461 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTrojanSpy.AutoIt.NEGASTEAL.SM.hp
F-ProtW32/AutoIt.OH.gen!Eldorado
APEXMalicious
AvastScript:SNH-gen [Trj]
GDataTrojan.GenericKD.33536266
KasperskyTrojan-PSW.MSIL.Agensla.nkf
AlibabaTrojan:Win32/AutoitU.ali2000008
ViRobotTrojan.Win32.Z.Autoit.1970688.B
TencentMsil.Trojan-qqpass.Qqrob.Wsao
Ad-AwareTrojan.GenericKD.33536266
EmsisoftTrojan.GenericKD.33536266 (B)
ComodoMalware@#2ep31994ud45x
F-SecureTrojan.TR/Autoit.abtcq
DrWebTrojan.AutoIt.771
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.69d6e48a969c8d47
SophosMal/Generic-S
IkarusTrojan-Spy.HawkEye
CyrenW32/AutoIt.OM.gen!Eldorado
AviraTR/Autoit.abtcq
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FFB90A
ZoneAlarmTrojan-PSW.MSIL.Agensla.nkf
MicrosoftTrojan:Win32/Occamy.C
TACHYONTrojan/W32.Agent.1970688.B
AhnLab-V3Trojan/AU3.Wacatac.S1079
Acronissuspicious
ALYacTrojan.Agent.HawkEye
MAXmalware (ai score=88)
VBA32Trojan.Autoit
MalwarebytesSpyware.AgentTesla
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.FDN
eGambitUnsafe.AI_Score_87%
FortinetAutoIt/Injector.FDH!tr
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.b26d54
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.MSIL.Agensla.nkf?

Trojan-PSW.MSIL.Agensla.nkf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment