Trojan

Trojan.Win32.Agent.newsnv removal

Malware Removal

The Trojan.Win32.Agent.newsnv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.newsnv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.newsnv?


File Info:

name: 4DD6986C9DA7D3504962.mlw
path: /opt/CAPEv2/storage/binaries/f4db77834a5fd672c48f03868949e7f6dbb931157690ac0852505d45ef155025
crc32: 3171A756
md5: 4dd6986c9da7d350496272e928962780
sha1: d1dace7be2fa08fd39f42896db3688ac566df4c8
sha256: f4db77834a5fd672c48f03868949e7f6dbb931157690ac0852505d45ef155025
sha512: b4aa6cf09fd76da801683eb7688266482f157dcf936a0e32c6abf6b934bd01b152814538ba1a2a5fe2caa58db640234fac837a66ee96c6b0b30a6be03a6c76c4
ssdeep: 24576:+jjcXsaPBHkuc5PHY64X5spOST31HpJU3vz5SZGn24sn:xXsKcVZp6LvU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FA258216F620D51DE44280F4BD99DA967A546CF20288B817F782EF4972B13E7ACF470B
sha3_384: 624e577fcce250d34feaed244a08c3a1a239d2aa056b89bc04fe61eff7768d137bf61f2380662ea12875e7fb13ef39e7
ep_bytes: 6864a64000e8eeffffff000000000000
timestamp: 2016-07-20 15:42:59

Version Info:

Translation: 0x0409 0x04b0
CompanyName: znwqzq
ProductName: nyopsu
FileVersion: 1.00
ProductVersion: 1.00
InternalName: a
OriginalFilename: a.exe

Trojan.Win32.Agent.newsnv also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.MLT.1
FireEyeGeneric.mg.4dd6986c9da7d350
McAfeeGenericRXPH-LD!4DD6986C9DA7
CylanceUnsafe
VIPRELooksLike.Win32.Malware!vb (v)
SangforTrojan.Win32.Save.a
K7AntiVirusNetWorm ( 700000151 )
BitDefenderGen:Heur.PonyStealer.MLT.1
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.c9da7d
VirITTrojan.Win32.VB_Heur
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Bancos.AAO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Dialog-9873788-0
KasperskyTrojan.Win32.Agent.newsnv
AvastWin32:GenMalicious-XO [Trj]
TencentMalware.Win32.Gencirc.114b71fa
Ad-AwareGen:Heur.PonyStealer.MLT.1
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanSpy.Bancos.KHO@5rvpl2
DrWebTrojan.DownLoader22.21183
TrendMicroTROJ_GEN.R002C0PL921
McAfee-GW-EditionGenericRXPH-LD!4DD6986C9DA7
EmsisoftGen:Heur.PonyStealer.MLT.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.PonyStealer.MLT.1
JiangminTrojan.Agent.ahou
AviraTR/ATRAPS.Gen2
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.1A253AD
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.Cossta.R218005
BitDefenderThetaAI:Packer.F6F51DD920
ALYacGen:Heur.PonyStealer.MLT.1
VBA32Trojan.Agent
MalwarebytesMalware.AI.1930929639
TrendMicro-HouseCallTROJ_GEN.R002C0PL921
YandexTrojan.GenAsa!mK1fh9obrmo
IkarusTrojan.Win32.Cossta
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Bancos.ACMB!tr
AVGWin32:GenMalicious-XO [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Agent.newsnv?

Trojan.Win32.Agent.newsnv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment