Spy Trojan

Trojan.Spy.Agent.OKP information

Malware Removal

The Trojan.Spy.Agent.OKP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Agent.OKP virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Spy.Agent.OKP?


File Info:

name: D3DDB9FE429714D89637.mlw
path: /opt/CAPEv2/storage/binaries/610e638e19e0e344918f61e9ddfbaae70541d85f429f8da5984aeee578559974
crc32: 421E38BA
md5: d3ddb9fe429714d896379badcd52f337
sha1: 4fd291ba17d45f5ebb541cf0fd756f54849a56b9
sha256: 610e638e19e0e344918f61e9ddfbaae70541d85f429f8da5984aeee578559974
sha512: 96eda242cf13741d803d3512cb884225fd25dda0185cc39fb4707b323d810b7b2ac63248aa8cb42bce7a54e1c72a7e3e5f3eb90d2224a743149f9b44d5b60cb6
ssdeep: 384:coaptRgcTKC+o4Ni10mVT6dHTxd72u1AAAAAAAfz:8lZbMaHV+dHTL72r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182B2D886EB879859D27205F255BBEB7222367D19EB354D8F50C132320DB32C1587EE0A
sha3_384: 409aa8b2aeac15e14ce5dda245ec6090e87d3154e68ee6a6c6c8766f98a26de24f14c40584a9c62f5430918b940cec7d
ep_bytes: 558bec8d3d50414000e892f1ffff85c0
timestamp: 2008-06-21 20:25:00

Version Info:

CompanyName: Lavatoch
FileDescription: Lavatoch Inc.
FileVersion: Version 1.0.0.4
InternalName: Lavatoch
LegalCopyright: Copyright by Lavatoch Inc.
OriginalFilename: Lavatoch
Translation: 0x0413 0x04b0

Trojan.Spy.Agent.OKP also known as:

BkavW32.FamVT.GeND.Trojan
LionicTrojan.Win32.Generic.lZ5Q
Elasticmalicious (high confidence)
DrWebTrojan.Upatre.100
MicroWorld-eScanTrojan.Spy.Agent.OKP
FireEyeGeneric.mg.d3ddb9fe429714d8
CAT-QuickHealTrojanDwnldr.Upatre.AA4
SkyhighBehavesLike.Win32.Downloader.mm
ALYacTrojan.Spy.Agent.OKP
MalwarebytesTrojan.Upatre
VIPRETrojan.Spy.Agent.OKP
SangforDownloader.Win32.Upatre.Vkid
K7AntiVirusTrojan ( 004afb631 )
BitDefenderTrojan.Spy.Agent.OKP
K7GWTrojan-Downloader ( 0048f6391 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Spy.Agent.OKP
BitDefenderThetaGen:NN.ZexaF.36792.bq1@aGZRV4iO
VirITTrojan.Win32.Dropper.IR
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Waski.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Generickd-1153
KasperskyTrojan-Downloader.Win32.Upatre.ehh
AlibabaTrojanDownloader:Win32/Upatre.5b029fcd
NANO-AntivirusTrojan.Win32.Upatre.dhbruu
ViRobotTrojan.Win.Z.Upatre.25090.V
RisingDownloader.Upatre!8.B5 (TFE:2:88pZZcF4MOE)
SophosTroj/Agent-AJNL
F-SecureTrojan-Downloader:W32/Upatre.I
BaiduWin32.Trojan-Downloader.Waski.a
ZillyaDownloader.Upatre.Win32.83
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Spy.Agent.OKP (B)
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojanDownloader.Upatre.em
WebrootTrojan.Dropper.Gen
VaristW32/Trojan.OLMN-6449
AviraTR/Rogue.pdau
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.Upatre
Kingsoftmalware.kb.a.997
XcitiumTrojWare.Win32.Kryptik.CNYX@5gkfaq
MicrosoftTrojanDownloader:Win32/Upatre
ZoneAlarmTrojan-Downloader.Win32.Upatre.ehh
GDataTrojan.Spy.Agent.OKP
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.C609118
Acronissuspicious
McAfeeUpatre-FAAA!D3DDB9FE4297
DeepInstinctMALICIOUS
VBA32TrojanDownloader.Upatre
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.26720
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentMalware.Win32.Gencirc.10b5390a
YandexTrojan.DL.Upatre!v6DMiQazHgM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AULH [Trj]
Cybereasonmalicious.a17d45
AvastWin32:Agent-AULH [Trj]

How to remove Trojan.Spy.Agent.OKP?

Trojan.Spy.Agent.OKP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment