Malware

Win32/Agent.AAZA information

Malware Removal

The Win32/Agent.AAZA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.AAZA virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Win32/Agent.AAZA?


File Info:

crc32: F3B6CD7E
md5: 319b9a928efef3da7fc72c1a776ca0e1
name: sox.exe
sha1: 31f679d3e22f1997d52ea73dd9ce94e060a3f0bf
sha256: 39f614d44ee12e8b9ab9ee1fe5e8db6935f3499cfde1842c97320ecb3dcf31d1
sha512: 40399d58a1683a34c24fca7bcdfad93fca76838203a29dc19a97c5572fc9c42305abbc1de9cc31f0c6d1e4cc9d48954346651f53c07bfdd41eac296354095380
ssdeep: 6144:pML3D97keJG331H5Mv2YkRkuBZMRjZXuSb:pM/tJ81Hav2YakYuRjZX7
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: KUMASERSOFT (c) 2015 Company
CompanyName: KUMASERSOFT
Comments: Pluralization Occlusion Substantially Realm
ProductName: QuantitativeInnerexceptions
ProductVersion: 4.2.6.547
FileDescription: Pluralization Occlusion Substantially Realm
Translation: 0x0409 0x04b0

Win32/Agent.AAZA also known as:

MicroWorld-eScanTrojan.GenericKD.32882272
McAfeeArtemis!319B9A928EFE
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32882272
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3e22f1
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.AAZA
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Proxy.Win32.Sybici.iy
RisingTrojan.Generic@ML.80 (RDMK:OMGxrKAcZ5W6aI0aGQ6MgA)
Ad-AwareTrojan.GenericKD.32882272
EmsisoftTrojan.GenericKD.32882272 (B)
F-SecureTrojan.TR/AD.Coroxy.tsteo
McAfee-GW-EditionBehavesLike.Win32.BadFile.cc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.319b9a928efef3da
IkarusTrojan.Coroxy
WebrootW32.Trojan.Gen
AviraTR/AD.Coroxy.tsteo
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D1F5BE60
ZoneAlarmTrojan-Proxy.Win32.Sybici.iy
MicrosoftTrojan:Win32/Detplock
Acronissuspicious
ALYacTrojan.GenericKD.32882272
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_95%
GDataTrojan.GenericKD.32882272
BitDefenderThetaGen:NN.ZexaF.33558.mmKfa8I!4Ndi
AVGFileRepMetagen [Malware]
AvastFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Win32/Agent.AAZA?

Win32/Agent.AAZA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment