Malware

Application.Agent.GGZ (file analysis)

Malware Removal

The Application.Agent.GGZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.GGZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Application.Agent.GGZ?


File Info:

crc32: C292AE6D
md5: 9420554c2a38ede71b8119ac292a26cb
name: 9420554C2A38EDE71B8119AC292A26CB.mlw
sha1: b8036bf862450b314de3b03f655caf2204c57571
sha256: 8243e4c357e56c0cd45fd67c1b3c67d54880896d655d2108d69c8f59e1075583
sha512: a166e5c2884a506ae2001a64051296c4b8a5aa6e3af1ecaad4e21e32b05e6e1bc48a01accfc350f62fb709e4095fc715dbc48b993fbb34c5602c94af69aaabec
ssdeep: 49152:XOGTXWJ+NBECxfIjS7kAUdrqoSxJlP3mH9Ub8Db:NTe+PECxFUITlP3jgb
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) x4f5cx8005 2014
InternalName: x559dx6c34x95f9x949f
FileVersion: 0.0.0.62
CompanyName: x6c34x5b9dx5b9dx4e4bx559dx6c34x95f9x949f
ProductName: x6c34x5b9dx5b9d
ProductVersion: 1.0.0.18
FileDescription: x5b9ax65f6x63d0x9192x60a8x8be5x559dx6c34x5566xff01
OriginalFilename: WaterClock.exe
Translation: 0x0009 0x04b0

Application.Agent.GGZ also known as:

K7AntiVirusHacktool ( 004baa361 )
Elasticmalicious (high confidence)
DrWebTrojan.Click3.9036
CylanceUnsafe
ZillyaTrojan.Diztakun.Win32.129
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaHackTool:Win32/Inject.cf083805
K7GWHacktool ( 004baa361 )
Cybereasonmalicious.c2a38e
SymantecTrojan.Gen.2
ESET-NOD32Win32/HackTool.Agent.NBW
APEXMalicious
AvastWin32:Malware-gen
BitDefenderApplication.Agent.GGZ
NANO-AntivirusTrojan.Win32.Agent.dctyjm
MicroWorld-eScanApplication.Agent.GGZ
Ad-AwareApplication.Agent.GGZ
SophosGeneric PUA LI (PUA)
BitDefenderThetaGen:NN.ZexaF.34298.8nKfae5ZL!jG
VIPRETrojan.Win32.Generic!BT
InvinceaGeneric PUA LI (PUA)
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGeneric.mg.9420554c2a38ede7
EmsisoftApplication.Agent.GGZ (B)
SentinelOneDFI – Malicious PE
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitApplication.Agent.GGZ
AegisLabVirus.Win32.Alman.mAYo
GDataApplication.Agent.GGZ
AhnLab-V3Trojan/Win32.HDC.C496364
McAfeeArtemis!9420554C2A38
MAXmalware (ai score=73)
VBA32TrojanDropper.Agent
MalwarebytesTrojan.Downloader
YandexRiskware.Agent!
IkarusTrojan.Inject2
FortinetRiskware/Agent
AVGWin32:Malware-gen

How to remove Application.Agent.GGZ?

Application.Agent.GGZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment