Trojan

About “Trojan-PSW.MSIL.Agensla.nwd” infection

Malware Removal

The Trojan-PSW.MSIL.Agensla.nwd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Agensla.nwd virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-PSW.MSIL.Agensla.nwd?


File Info:

crc32: 295582CA
md5: a2ac38d252da2adb43ec67cb9f0e5ed4
name: mezz.exe
sha1: 8835a17b415c2e4325180712ed950543c0ff95a0
sha256: 42b74608b3445a56f60fd25248052c7dde4726996af2102ae31df0efb941c5f6
sha512: 9d7b6f7c24984f25ad41f70530ca66410e45f685cc744ff0eab1175145c6ae668d142f51cc64dbab0dd6d4597f37a5db11e91c718145ca56549b6073af80d72c
ssdeep: 24576:Otb20pkaCqT5TBWgNQ7aS7TvV+9EvLG5CsuYH5E807+Q6A:7Vg5tQ7aS7TFLG3Y75
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-PSW.MSIL.Agensla.nwd also known as:

MicroWorld-eScanTrojan.GenericKD.33553757
McAfeeArtemis!A2AC38D252DA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusTrojan ( 00562e1a1 )
BitDefenderTrojan.GenericKD.33553757
K7GWTrojan ( 00562e1a1 )
Cybereasonmalicious.b415c2
TrendMicroTROJ_GEN.R011C0DCJ20
APEXMalicious
AvastScript:SNH-gen [Trj]
GDataWin32.Trojan-Stealer.AgentTesla.7LJ43I
KasperskyTrojan-PSW.MSIL.Agensla.nwd
AlibabaTrojan:Win32/AutoitU.ali2000008
RisingTrojan.Obfus/Autoit!1.C408 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33553757 (B)
F-SecureHeuristic.HEUR/AGEN.1045422
DrWebTrojan.Inject2.20390
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a2ac38d252da2adb
SophosMal/Generic-S
IkarusTrojan.Autoit
CyrenW32/AutoIt.OM.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1045422
ArcabitTrojan.Generic.D1FFFD5D
ZoneAlarmTrojan-PSW.MSIL.Agensla.nwd
MicrosoftTrojan:Win32/Predator.BD!MTB
AhnLab-V3Trojan/AU3.Wacatac.S1079
Acronissuspicious
ALYacTrojan.GenericKD.33553757
MAXmalware (ai score=100)
Ad-AwareTrojan.GenericKD.33553757
MalwarebytesSpyware.PasswordStealer.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.FDY
TrendMicro-HouseCallTROJ_GEN.R011C0DCJ20
TencentMsil.Trojan-qqpass.Qqrob.Lmau
eGambitUnsafe.AI_Score_85%
FortinetAutoIt/Injector.ESJ!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.PSW.7b7

How to remove Trojan-PSW.MSIL.Agensla.nwd?

Trojan-PSW.MSIL.Agensla.nwd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment