Malware

RAR/Agent.AZ malicious file

Malware Removal

The RAR/Agent.AZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RAR/Agent.AZ virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup

How to determine RAR/Agent.AZ?


File Info:

crc32: E522E79E
md5: 15ab92bb1ad485957d8219954040b1b9
name: 15AB92BB1AD485957D8219954040B1B9.mlw
sha1: 1714785ef4a3ed2a5500ea7103f05b81750343c7
sha256: 73ed049e6144a973e51a9c316a97927bcfa32cfe0d67b7fa2e3bd682533b25c8
sha512: baa6f18c003f2b59d6f92738f7ba9b96eef57268dbe3a1a41d3a5cd15920b0da8c2aab21078eedde5db83cfda4b14a5a59249659af696bbcae075d3bcbd7ef3a
ssdeep: 6144:L84RgnS1flEedzyzWPqyv9O/CH/tMRt+pQwupxvu/MaxYWR:A4RzfZdzyiPxq2tYsKwmxveMavR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

RAR/Agent.AZ also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.DownLoader35.32803
MicroWorld-eScanTrojan.Rasftuby.Gen.11
FireEyeGeneric.mg.15ab92bb1ad48595
Qihoo-360Win32/Trojan.de2
ALYacTrojan.Rasftuby.Gen.11
CylanceUnsafe
SUPERAntiSpywareBackdoor.CyberGate/Variant
K7AntiVirusTrojan ( 004b92dc1 )
AlibabaTrojanDropper:Win32/Slipafext.c0fd2cfb
K7GWTrojan ( 004b92dc1 )
CrowdStrikewin/malicious_confidence_100% (W)
InvinceaMal/RarMal-E
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Agent.gen
BitDefenderTrojan.Rasftuby.Gen.11
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
Ad-AwareTrojan.Rasftuby.Gen.11
EmsisoftTrojan.Rasftuby.Gen.11 (B)
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Patched.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06EC0DKG20
McAfee-GW-EditionRDN/Generic Dropper
SophosMal/RarMal-E
GDataMSIL.Backdoor.Bladabindi.WKXEDI
JiangminBackdoor.Xtreme.blw
AviraTR/Patched.Gen
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Rasftuby.Gen.11
ZoneAlarmTrojan.Win32.Agent.gen
MicrosoftTrojanDropper:Win32/Slipafext.A
CynetMalicious (score: 85)
McAfeeRDN/Generic Dropper
MAXmalware (ai score=84)
MalwarebytesBackdoor.NJRat
ESET-NOD32RAR/Agent.AZ
TrendMicro-HouseCallTROJ_GEN.R06EC0DKG20
TencentWin32.Trojan.Dropper.Dyqt
FortinetW32/Agent.AZ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.b1ad48

How to remove RAR/Agent.AZ?

RAR/Agent.AZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment