Malware

BAT/Agent.ORW removal tips

Malware Removal

The BAT/Agent.ORW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Agent.ORW virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine BAT/Agent.ORW?


File Info:

crc32: 16FF05E5
md5: 74591868009931796b3e04d3f243cad3
name: 74591868009931796B3E04D3F243CAD3.mlw
sha1: e2be729c676f5c2a25ed17f2409244b98825f719
sha256: 339f502c2efe2b3ad9bc02e918929de3c173946f16833a751cacd5c87cf5bb7f
sha512: c3460e4f756b177f7e265881442a73a13be422bed7808eb3c1904690566575decd0340c4a52c779a02bb9f72189f2225c1991808d0d4379ea31e543273d62c43
ssdeep: 192:cONz9D3S8G6mo1SEFaNJhLkwcud2DH9VwGfct8uH:cmDimHSQaNJawcudoD7UWQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

BAT/Agent.ORW also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005482911 )
DrWebTrojan.Muldrop8.41845
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Bot.S19311
ALYacTrojan.Autoruns.GenericKD.32946821
CylanceUnsafe
SangforTrojan.BAT.Agent.gen
AlibabaTrojan:BAT/Generic.cc91ec4c
K7GWTrojan ( 005482911 )
Cybereasonmalicious.800993
CyrenW32/Barys.V.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Agent.ORW
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.BAT.Agent.gen
BitDefenderTrojan.Autoruns.GenericKD.32946821
NANO-AntivirusTrojan.Win32.Drop.fmyrjo
MicroWorld-eScanTrojan.Autoruns.GenericKD.32946821
TencentWin32.Trojan.Drpr.Agbh
Ad-AwareTrojan.Autoruns.GenericKD.32946821
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDropper.Agent.DT@6n86dy
BitDefenderThetaAI:Packer.660E93621E
McAfee-GW-EditionBehavesLike.Win32.Agent.xc
FireEyeGeneric.mg.7459186800993179
EmsisoftTrojan.Autoruns.GenericKD.32946821 (B)
SentinelOneStatic AI – Suspicious PE
AviraBAT/Agent.udrkk
MicrosoftTrojan:Win32/Occamy.AA
SUPERAntiSpywareTrojan.Agent/Gen-Muldrop
GDataTrojan.Autoruns.GenericKD.32946821
Acronissuspicious
McAfeeArtemis!745918680099
VBA32Trojan.Agent
MalwarebytesTrojan.Agent.UPX.Generic
PandaTrj/CI.A
RisingTrojan.Win32.Muldrop.b (CLASSIC)
IkarusTrojan.BAT.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
FortinetBAT/Agent.ORW!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove BAT/Agent.ORW?

BAT/Agent.ORW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment