Malware

JS/Agent.OHD malicious file

Malware Removal

The JS/Agent.OHD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What JS/Agent.OHD virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
dj-updates.com
bits.avcdn.net
download.yandex.ru
cache-mskm905.cdn.yandex.net

How to determine JS/Agent.OHD?


File Info:

crc32: F5FCC527
md5: 185a45447af493058751bba2913b84a6
name: test_fail.exe
sha1: e0545d8890b07fbca6eef72702fa1b4531d84fda
sha256: 544f3b83b113b3cf0c1aeb29d81b339f7319edceb712866623100fdf3939b1b3
sha512: e2e16300823194e736293d38f3433da6d7db007061689da957c7d5d0a5e4060f60cb84f3ca2f76a294bf429499ba6526c300b923e4cf33a4a410178db7cd112d
ssdeep: 196608:wZdwuTV1lBmCZcILlVegdpxAlxBGzgcP/10oJTjZrJppQSZO6:wZdwuTVLBeKlhxA0z5PGoJTjlJ7QO7
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription: Setup VK DJ
OriginalFilename:
Translation: 0x0419 0x04e3

JS/Agent.OHD also known as:

DrWebProgram.VKontakteDJ.74
MicroWorld-eScanGen:Variant.Strictor.236902
FireEyeGeneric.mg.185a45447af49305
ALYacGen:Variant.Strictor.236902
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Scrami.4!c
SangforMalware
BitDefenderGen:Variant.Strictor.236902
K7GWTrojan ( 0055dbb61 )
K7AntiVirusTrojan ( 0055dbb61 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PUPX-gen [PUP]
GDataGen:Variant.Strictor.236902
KasperskyTrojan.Win32.Scrami.avo
AlibabaTrojan:Win32/Scrami.2baa01ab
NANO-AntivirusTrojan.Win32.Scrami.hbsjkk
TencentWin32.Trojan.Scrami.Dxxa
Ad-AwareGen:Variant.Strictor.236902
EmsisoftGen:Variant.Strictor.236902 (B)
ComodoMalware@#g74zsuhgt9s5
F-SecureHeuristic.HEUR/AGEN.1133947
ZillyaTrojan.Scrami.Win32.328
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
IkarusTrojan.JS.Agent
AviraHEUR/AGEN.1133947
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.VKontakte.dj
Endgamemalicious (high confidence)
ArcabitTrojan.Strictor.D39D66
ZoneAlarmTrojan.Win32.Scrami.avo
MicrosoftPUA:Win32/MediaDrug
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.Agent.R309505
McAfeeArtemis!185A45447AF4
VBA32BScope.Trojan.Skeeyah
MalwarebytesPUP.Optional.VkontakteDJ
PandaTrj/Genetic.gen
ESET-NOD32a variant of JS/Agent.OHD
RisingPUA.MediaDrug!8.4979 (TFE:dGZlOgWnXstx6FgL4w)
FortinetW32/VKontakte.DJ!tr
WebrootW32.Trojan.Gen
AVGWin32:PUPX-gen [PUP]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM41.2.263B.Malware.Gen

How to remove JS/Agent.OHD?

JS/Agent.OHD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment