Trojan

TrojanClicker:Win32/Agent.S removal

Malware Removal

The TrojanClicker:Win32/Agent.S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanClicker:Win32/Agent.S virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanClicker:Win32/Agent.S?


File Info:

name: D288B51C703968EF5943.mlw
path: /opt/CAPEv2/storage/binaries/66473a1e0c8d774938e95bab702e0cb62e344174d5a77f5db4a8c56a8f0a01ca
crc32: 9FFA2AC6
md5: d288b51c703968ef59434e458ee983be
sha1: 918cb9fb1e66c6ff22995874d06b39cf7eecec9f
sha256: 66473a1e0c8d774938e95bab702e0cb62e344174d5a77f5db4a8c56a8f0a01ca
sha512: 2a1e90d35bbfce4e57f9df5ccd0606d92bd7883b2d48b4a30b6af879467e677541832628783bc24a3d0d213df1d84ea59a685e60237a684e98829dd7f4ad04bf
ssdeep: 3072:xqBFJLzgOJJ0Yrba0fe+CUGXQV8HiKxh2pvFr:wPdZA4/fvtGXQV8CyEfr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17EC3F11377D09857EF9B5A32517FCB39D7F78A6004229C5783217EBA2E343825B2A742
sha3_384: 06720e43e7e010dfc95f918ab07259b7865f66055ec1cb6ff99a4883ec08389ce520e55ffb6fc0e28f5188e92eaf4ccf
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:12

Version Info:

0: [No Data]

TrojanClicker:Win32/Agent.S also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.NSIS.4!c
MicroWorld-eScanGen:Variant.Nemesis.1730
ClamAVWin.Trojan.NSIS-30
FireEyeGen:Variant.Nemesis.1730
CAT-QuickHealTrojanClicker.NSIS.Agent.S
SkyhighBehavesLike.Win32.GenDownloader.cc
McAfeeArtemis!D288B51C7039
MalwarebytesTrojan.Clicker.Generic
VIPREGen:Variant.Nemesis.1730
SangforDownloader.Win32.Clicker.Vxo7
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanClicker:Win32/Snojan.d5365bae
K7GWTrojan-Downloader ( 0026b1c11 )
K7AntiVirusTrojan-Downloader ( 0026b1c11 )
ArcabitTrojan.Nemesis.D6C2
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32NSIS/TrojanDownloader.Agent.NHJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Clicker.Win32.NSIS.bb
BitDefenderGen:Variant.Nemesis.1730
NANO-AntivirusTrojan.Nsis.Agent.bstmny
AvastNSIS:Downloader-QF [Trj]
TencentTrojan.Win32.Clicker.aad
EmsisoftGen:Variant.Nemesis.1730 (B)
F-SecureTrojan.TR/Agent.ank.3
ZillyaTrojan.Snojan.Win32.5711
TrendMicroTROJ_CLICKR.SMIE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.adyzj
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Agent.ank.3
MAXmalware (ai score=80)
Antiy-AVLTrojan[Clicker]/Win32.NSIS.bb
Kingsoftmalware.kb.a.996
MicrosoftTrojanClicker:Win32/Agent.S
ZoneAlarmTrojan-Clicker.Win32.NSIS.bb
GDataGen:Variant.Nemesis.1730
VaristW32/NSIS_Agent.O.gen!Eldorado
AhnLab-V3Trojan/Win32.NSIS.R7368
VBA32Trojan.MulDrop
ALYacGen:Variant.Nemesis.1730
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.Win32.AVplayer.l (CLASSIC)
IkarusTrojan-Clicker.Win32.NSIS
FortinetW32/ClickerNSS.BA!tr
AVGNSIS:Downloader-QF [Trj]
Cybereasonmalicious.b1e66c
DeepInstinctMALICIOUS

How to remove TrojanClicker:Win32/Agent.S?

TrojanClicker:Win32/Agent.S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment