Win32/PSW.Agent.NLT [Threat Name] go to Threat

Win32/PSW.Agent.NLT [Threat Variant Name]

Category trojan
Size 21513 B
Detection created Jun 17, 2009
Detection database version 4163
Aliases Trojan-Downloader.Win32.Small.alhe (Kaspersky)
  Generic.Downloader.x!gc (McAfee)
  PWS:Win32/Fignotok.A (Microsoft)
Short description

Win32/PSW.Agent.NLT is a trojan that steals passwords and other sensitive information. The trojan can send the information to a remote machine.


The trojan does not create any copies of itself.

Information stealing

The trojan collects information related to the following applications:

  • DynDNS Updater
  • FileZilla
  • FlashFXP
  • Google Talk
  • Internet Explorer
  • Mozilla Firefox
  • No-IP Windows Dynamic Update Client
  • PalTalk
  • Pidgin
  • Steam
  • Trillian
  • Windows Live ID

The trojan can send the information to a remote machine.

The HTTP protocol is used.

The trojan contains a list of (1) URLs.

Other information

The trojan quits immediately if any of the following applications is detected:

  • Process Monitor (Sysinternals)

The trojan quits immediately if it is run within a debugger.

Please enable Javascript to ensure correct displaying of this content and refresh this page.