MSIL/Spy.Agent.PI [Threat Name] go to Threat

MSIL/Spy.Agent.PI [Threat Variant Name]

Category trojan
Size 553984 B
Detection created Nov 29, 2013
Detection database version 9110
Aliases Trojan.MSIL.Inject.gsz (Kaspersky)
  Trojan:Win32/Malagent (Microsoft)
  TR/Spy.Agent.PI.38 (Avira)
Short description

MSIL/Spy.Agent.PI is a trojan that steals sensitive information. The trojan attempts to send gathered information to a remote machine.

Installation

The trojan does not create any copies of itself.


Information stealing

MSIL/Spy.Agent.PI is a trojan that steals sensitive information.


The trojan collects the following information:

  • data from the clipboard
  • screenshots
  • computer IP address
  • CPU information
  • computer name
  • login passwords for certain applications/services

The trojan attempts to send gathered information to a remote machine.


The trojan contains a URL address. The HTTP protocol is used.

Other information

The trojan contains the program code of the following malware:

  • MSIL/PSW.Agent.NUM trojan

The trojan creates and runs a new thread with its own program code within the following processes:

  • %malwarefilepath%

The trojan may create the following folders:

  • %appdata%\­Microsoft\­
  • %appdata%\­Microsoft\­Backups\­

Trojan requires the Microsoft .NET Framework to run.

Please enable Javascript to ensure correct displaying of this content and refresh this page.