Trojan

TrojanPWS.Agent removal

Malware Removal

The TrojanPWS.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPWS.Agent virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Starts servers listening on 127.0.0.1:0
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity contains more than one unique useragent.
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to disable Windows Defender
  • Attempts to create or modify system certificates
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
wensela.xyz
t.gogamec.com
www.listincode.com
cdn.discordapp.com
ocsp.digicert.com
apps.identrust.com
statuse.digitalcertvalidation.com
gcl-gb.biz
iplogger.org
ipinfo.io
ppgggb.com
privacytoolzforyou7000.top
dataonestorage.com
cikgushashi.com
www.mrwenshen.com
el5en1977834657.s3.ap-south-1.amazonaws.com
dumancue.com

How to determine TrojanPWS.Agent?


File Info:

crc32: 66BA4325
md5: 19cd03dcd7f974e6b526330682cf7136
name: 19CD03DCD7F974E6B526330682CF7136.mlw
sha1: 03a3a90af5e78e7dd35e398177f3b681a5f77f4d
sha256: 930424b3b89131f4b2a5d46849ec3a7295ac5ee22255acea9a950aa87817f873
sha512: 22ae5d4ffb7f95f39805d9af4b9538be0a87b2d5dfdaf597facb4132af72556d6acfbcc9abf9092a79fc186ce6ca31f01eff302a5070c0463d8dea8c1330cfbb
ssdeep: 98304:xLCvLUBsgKTdiSQahDunZyhzs2dx/BOEJ/aC6FbH7:xwLUCgKRiUGZmXJOEJaC6Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
InternalName: 7zS.sfx
FileVersion: 19.00
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 19.00
FileDescription: 7z Setup SFX
OriginalFilename: 7zS.sfx.exe
Translation: 0x0409 0x04b0

TrojanPWS.Agent also known as:

K7AntiVirusTrojan ( 0056b4921 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.4515
ClamAVWin.Packed.Barys-9859531-0
CAT-QuickHealTrojanPWS.Agent
CylanceUnsafe
K7GWTrojan ( 0056b4921 )
Cybereasonmalicious.cd7f97
CyrenW32/Kryptik.FOQ.gen!Eldorado
ESET-NOD32multiple detections
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Jaik.45703
MicroWorld-eScanGen:Variant.Jaik.45703
Ad-AwareGen:Variant.Jaik.45703
SophosML/PE-A + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZedlaF.34236.n88baOE@FOp
TrendMicroTROJ_GEN.R002C0WJV21
McAfee-GW-EditionRDN/Generic Downloader.x
FireEyeGen:Variant.Jaik.45703
EmsisoftGen:Variant.Jaik.45703 (B)
JiangminTrojan.Zapchast.rz
AviraTR/Agent.tzwta
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.3454962
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftRansom:Win32/StopCrypt.MAQK!MTB
GDataGen:Variant.Jaik.45703
VBA32Malware-Cryptor.2LA.gen
MAXmalware (ai score=84)
MalwarebytesTrojan.Dropper.SFX.Generic
TrendMicro-HouseCallTROJ_GEN.R002H0DJV21
RisingTrojan.Starter!1.D93D (CLASSIC)
FortinetW32/BSE.4Q7Q!tr
AVGWin32:MalwareX-gen [Trj]

How to remove TrojanPWS.Agent?

TrojanPWS.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment