Trojan

TrojanClicker:Win32/Agent.S information

Malware Removal

The TrojanClicker:Win32/Agent.S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanClicker:Win32/Agent.S virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanClicker:Win32/Agent.S?


File Info:

name: A8E67D6E2846420F608D.mlw
path: /opt/CAPEv2/storage/binaries/bcd7e0f59b47588f74f85a68ac90b19ebf48259c08fe1145de78498981d5f90e
crc32: 2058D5CB
md5: a8e67d6e2846420f608de548b9d0a432
sha1: 862359b25d29b7c2b8cb6cb7346e09180fdc0a2b
sha256: bcd7e0f59b47588f74f85a68ac90b19ebf48259c08fe1145de78498981d5f90e
sha512: 7042948c390d00c076958fbddd85d7a30e22a8babcf33ce63a10717d249107907f4d3999be5a229db9ba752429bbc5b8a9bca43bb18f97405ab13d70eb708071
ssdeep: 3072:xqBFJLzgOJJQa0fe+CUGXQV8HiKxh2pvFo:wPdZQfvtGXQV8CyEfo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BDC3F15377D0A457DF974632516BCB39D7F78A6004129C5B87213EFA3E342825B2A707
sha3_384: 4247ed0110fc1a1657b29ad689b8cd6953ee112f61e6ef55d6ab73279a7fbcef164d18bbe0943b6536fb38700cdf2b46
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:12

Version Info:

0: [No Data]

TrojanClicker:Win32/Agent.S also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.NSIS.4!c
DrWebTrojan.DownLoader3.35746
MicroWorld-eScanGen:Variant.Nemesis.1730
ClamAVWin.Trojan.NSIS-30
FireEyeGen:Variant.Nemesis.1730
CAT-QuickHealTrojanClicker.NSIS.Agent.S
SkyhighBehavesLike.Win32.GenDownloader.cc
ALYacGen:Variant.Nemesis.1730
MalwarebytesTrojan.Clicker.Generic
ZillyaTrojan.NSIS.Win32.4372
SangforDownloader.Win32.Clicker.V30i
K7AntiVirusTrojan-Downloader ( 0026b1c11 )
AlibabaTrojanClicker:Win32/Snojan.9b377b1f
K7GWTrojan-Downloader ( 0026b1c11 )
Cybereasonmalicious.25d29b
ArcabitTrojan.Nemesis.D6C2
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32NSIS/TrojanDownloader.Agent.NHJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Clicker.Win32.NSIS.bb
BitDefenderGen:Variant.Nemesis.1730
NANO-AntivirusTrojan.Nsis.Agent.bstmny
AvastNSIS:Downloader-QF [Trj]
RisingTrojan.Win32.AVplayer.l (CLASSIC)
EmsisoftGen:Variant.Nemesis.1730 (B)
F-SecureTrojan.TR/Agent.ank.3
VIPREGen:Variant.Nemesis.1730
TrendMicroTROJ_CLICKR.SMIE
Trapminemalicious.high.ml.score
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.adyzj
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Agent.ank.3
MAXmalware (ai score=86)
Antiy-AVLTrojan[Clicker]/Win32.NSIS.bb
Kingsoftmalware.kb.a.997
MicrosoftTrojanClicker:Win32/Agent.S
ZoneAlarmTrojan-Clicker.Win32.NSIS.bb
GDataGen:Variant.Nemesis.1730
VaristW32/NSIS_Agent.O.gen!Eldorado
AhnLab-V3Trojan/Win32.NSIS.R7368
McAfeeArtemis!A8E67D6E2846
VBA32Trojan.MulDrop
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_CLICKR.SMIE
TencentTrojan.Win32.Clicker.aad
IkarusTrojan-Clicker.Win32.NSIS
FortinetW32/ClickerNSS.BA!tr
AVGNSIS:Downloader-QF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanClicker:Win32/Agent.S?

TrojanClicker:Win32/Agent.S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment