Trojan

Should I remove “Trojan-PSW.MSIL.Agensla.rvr”?

Malware Removal

The Trojan-PSW.MSIL.Agensla.rvr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Agensla.rvr virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares

How to determine Trojan-PSW.MSIL.Agensla.rvr?


File Info:

crc32: F39F7F82
md5: 2ab4308e7031e2b2ddbb44756f5b8ca9
name: tmp3mkgv58n
sha1: 297c36f65eeedad12525ffc5e00315df24e8f8e6
sha256: db835b1d8c0cb244f0ee4acc8aa757beab527b257756fa7ff17b2847388545c5
sha512: 203428b15b293dda05d7ef67bbacde17c9725aab843db9ea7d009bc1be4864c4489be5f7b7e375bf1a672fdb01881230f445b87527d6a676c2878dfceac1aafa
ssdeep: 24576:hAHnh+eWsN3skA4RV1Hom2KXMmHaNvT+AxCoTUUKClLdC/nXE5:4h+ZkldoPK8YaNyA0oCMJn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-PSW.MSIL.Agensla.rvr also known as:

BkavW32.AIDetectVM.malwareA
MicroWorld-eScanTrojan.GenericKD.34002609
FireEyeGeneric.mg.2ab4308e7031e2b2
CAT-QuickHealTrojan.Multi
McAfeeArtemis!2AB4308E7031
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanPSW:Win32/Agensla.1204d993
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.65eeed
ArcabitTrojan.Generic.D206D6B1
TrendMicroTrojan.Win32.WACATAC.USXVPFA20
CyrenW32/AutoIt.IJ.gen!Eldorado
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTrojan.Win32.WACATAC.USXVPFA20
AvastScript:SNH-gen [Trj]
ClamAVWin.Malware.Autoit-8013889-0
KasperskyTrojan-PSW.MSIL.Agensla.rvr
BitDefenderTrojan.GenericKD.34002609
Paloaltogeneric.ml
AegisLabHacktool.Win32.Gamehack.3!e
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.34002609 (B)
ComodoMalware@#3d2f948gswoaa
F-SecureTrojan.TR/AutoIt.oowfv
DrWebTrojan.Inject3.42025
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
SophosMal/Generic-S
APEXMalicious
F-ProtW32/AutoIt.IJ.gen!Eldorado
AviraTR/AutoIt.oowfv
MicrosoftTrojan:Win32/Predator.VA!MTB
ZoneAlarmTrojan-PSW.MSIL.Agensla.rvr
GDataTrojan.GenericKD.34002609
CynetMalicious (score: 100)
VBA32Trojan.Predator
ALYacTrojan.GenericKD.34002609
MAXmalware (ai score=83)
Ad-AwareTrojan.GenericKD.34002609
MalwarebytesSpyware.AgentTesla.AutoIt
ESET-NOD32a variant of Win32/Injector.Autoit.FIS
TencentWin32.Trojan.Autoit.Auto
YandexTrojan.Igent.bTTguf.77
IkarusTrojan-Spy.Keylogger.AgentTesla
eGambitUnsafe.AI_Score_98%
FortinetAutoIt/Injector.FIC!tr
AVGScript:SNH-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.PSW.bc9

How to remove Trojan-PSW.MSIL.Agensla.rvr?

Trojan-PSW.MSIL.Agensla.rvr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment