Malware

PowerShell/Agent.GZ removal guide

Malware Removal

The PowerShell/Agent.GZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PowerShell/Agent.GZ virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine PowerShell/Agent.GZ?


File Info:

name: 6B32E7B61AEF7E5106E6.mlw
path: /opt/CAPEv2/storage/binaries/2cb5e93ebb477be1ce03ec0aae93407437000194f48ce457586ea23614f9b51a
crc32: 9C1D14AE
md5: 6b32e7b61aef7e5106e6a1f915056574
sha1: a571971a6d8135685878fb2971345e7cd14ed265
sha256: 2cb5e93ebb477be1ce03ec0aae93407437000194f48ce457586ea23614f9b51a
sha512: b16ee85e5e67a8e0f99e1cf5f29e8d49feab386ddb007bf6723971f677eab7fb8e19727067a52746ed86ff3ab99a430d58d8e2be2a0a0c41665e9f09f6d217d8
ssdeep: 6144:e6rdcCkBC/XKmYP5MzczlzAh6ezzPzzzzbPnC26hPSQZep+Vahqf9Wk7:e6rdcCkwvKmA5aJ6hq3I9T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9A4071F25C8802FF333AAF577C1A7A815ABFEF96A15850A58E037D9BE75E836C05101
sha3_384: 253e9d98ae1609201f74b20041998928a6b54e44b77164fae08db11f07df7df7b2504648e08bb7e2b8ee7b88c9028ee2
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-21 03:56:06

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: run HENPRI.exe
LegalCopyright:
OriginalFilename: run HENPRI.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

PowerShell/Agent.GZ also known as:

BkavW32.AIDetectNet.01
LionicTrojan.PowerShell.ClipBanker.7!c
MicroWorld-eScanTrojan.GenericKD.50485788
FireEyeGeneric.mg.6b32e7b61aef7e51
ALYacTrojan.GenericKD.50485788
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005944231 )
AlibabaTrojanBanker:Win32/ClipBanker.9bb6a692
K7GWTrojan ( 005944231 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/ABRisk.DFRR-0223
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32PowerShell/Agent.GZ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Detected-9956421-0
KasperskyHEUR:Trojan-Banker.PowerShell.ClipBanker.gen
BitDefenderTrojan.GenericKD.50485788
AvastWin32:Trojan-gen
TencentWin32.Trojan-banker.Clipbanker.Wozq
Ad-AwareTrojan.GenericKD.50485788
ComodoMalware@#375u5geq2o9sw
VIPRETrojan.GenericKD.50485788
TrendMicroTROJ_GEN.R002C0PFQ22
McAfee-GW-EditionRDN/PWS-Banker
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusBZC.PZQ.Pantera
GDataMSIL.Trojan.PSE.R4KKU7
AviraTR/Agent.oobxt
Antiy-AVLTrojan/Generic.ASMalwS.80D5
KingsoftWin32.Troj.Banker.(kcloud)
ArcabitTrojan.Generic.D3025A1C
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.PWS-Banker.C5180387
McAfeeRDN/PWS-Banker
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R002C0PFQ22
RisingTrojan.Kryptik!1.DB9C (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.185135624.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34806.Dm0@aOjgEkk
AVGWin32:Trojan-gen
Cybereasonmalicious.a6d813
PandaTrj/GdSda.A

How to remove PowerShell/Agent.GZ?

PowerShell/Agent.GZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment