Malware

Win32/PSW.Agent.NTM malicious file

Malware Removal

The Win32/PSW.Agent.NTM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Agent.NTM virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/PSW.Agent.NTM?


File Info:

name: FC2F06B13FDBF4D9E120.mlw
path: /opt/CAPEv2/storage/binaries/16fc0547dfaa3262eeaa8c51c9973a79ba363fc849f1606ad2fa7f1e578f14ec
crc32: 355FA44D
md5: fc2f06b13fdbf4d9e120075cc02384e0
sha1: 6c9f1a3ec639e6aa0ac0d5e5f5b484a77969ed6a
sha256: 16fc0547dfaa3262eeaa8c51c9973a79ba363fc849f1606ad2fa7f1e578f14ec
sha512: 103167be1527f3a2fa4d15d7155cb8609eee675985151c64a2cb9a7591f3853c164b656f2caf2f90af37f1656b1e11070be8d140d49ade29cbbafe6b5dfb7da0
ssdeep: 3072:BfIZD9Yw/4+pFTBfRrUlaiRh2hApKmZwCn4npgkMuOHFpVwKpYl5d5+N3kIH9TTw:BSqw/4cTBJrUzRolf8FpVwKpqf5+p9u
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A734DF5173B0EC32E2B6063255D1C67896397952ABB483CF72ECB76EAD362901B343C5
sha3_384: ab796ee5a5d262a2382f61bcfbc02682cd6921dfd65f0225be7ae22e807182b87c08623b3296ba194995cce401d1c333
ep_bytes: 60be00c042008dbe0050fdff57eb0b90
timestamp: 2012-02-17 17:57:24

Version Info:

FileVersion: 2.0.2.1
PrivateBuild: 2003
ProductVersion: 2.0.2.1
Translation: 0x0809 0x04b0

Win32/PSW.Agent.NTM also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.Heur.KS.1
ClamAVWin.Malware.Cycbot-9789213-0
ALYacGen:Trojan.Heur.KS.1
Cylanceunsafe
SangforVirus.Win32.Save.a
AlibabaTrojanPSW:Win32/Yakes.d639c569
K7GWPassword-Stealer ( 002f7a301 )
Cybereasonmalicious.13fdbf
CyrenW32/Backdoor.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/PSW.Agent.NTM
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Yakes.abiej
BitDefenderGen:Trojan.Heur.KS.1
NANO-AntivirusTrojan.Win32.Gbot.kxccm
AvastWin32:Crypt-LLY [Trj]
TencentWin32.Trojan.Yakes.Mjgl
EmsisoftGen:Trojan.Heur.KS.1 (B)
F-SecureTrojan.TR/Rogue.kdv.538872
DrWebTrojan.PWS.Multi.363
VIPREGen:Trojan.Heur.KS.1
TrendMicroTROJ_GEN.R03BC0DF323
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.fc2f06b13fdbf4d9
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.KS.1
JiangminHeur:Trojan/Logogif
AviraTR/Rogue.kdv.538872
Antiy-AVLTrojan[Backdoor]/Win32.Gbot
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Heur.KS.1
ZoneAlarmTrojan.Win32.Yakes.abiej
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Backdoor/Win32.Gbot.R35572
Acronissuspicious
McAfeeArtemis!FC2F06B13FDB
MAXmalware (ai score=84)
VBA32SScope.Malware-Cryptor.Maxplus.0997
MalwarebytesMalware.AI.3780061787
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DF323
RisingBackdoor.Cycbot!1.9934 (CLOUD)
IkarusTrojan-PSW.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ULPM.16C0!tr
BitDefenderThetaAI:Packer.3B02961514
AVGWin32:Crypt-LLY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/PSW.Agent.NTM?

Win32/PSW.Agent.NTM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment