Malware

Win32/Agent.OCR information

Malware Removal

The Win32/Agent.OCR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.OCR virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Win32/Agent.OCR?


File Info:

name: 4D6C49F10E5D1B57AB0E.mlw
path: /opt/CAPEv2/storage/binaries/0d33c1e31baec55508b82e17154e4f66d780d9a71c7d896b3d9bb3410462510f
crc32: A493B527
md5: 4d6c49f10e5d1b57ab0e3db42c6db7be
sha1: 686b77ce7f17eee7cdd2987bf15d686d0368263a
sha256: 0d33c1e31baec55508b82e17154e4f66d780d9a71c7d896b3d9bb3410462510f
sha512: d3e676abf0d012afdc4de94baaaeae8bc48d3f572678fda7bc4421767abfa27c9855eccc2390ca55a352df088a76fb4f0ebfd786e9bb8333125a9bac76a35b70
ssdeep: 6144:oX42tUDf+jG2zhQTIv2DotRjmtTB3b6uv:VjdTc2AmtTx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14726E7A165CD48F2C49AB43D0D68F270D1E1D9A8CF2055E7AFEE0F0BBC125A44AB1F56
sha3_384: 99a9fbbf87b7f8d2933e4721fb54b6739b00922b26d04a2542e0856f71b0948c4c7e511ddfe74838d91252f7148d098e
ep_bytes: 558bec6aff68d02b430068aecf420064
timestamp: 2010-07-26 07:15:17

Version Info:

0: [No Data]

Win32/Agent.OCR also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.ljdO
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Mikey.116104
FireEyeGeneric.mg.4d6c49f10e5d1b57
SkyhighDownloader-BZH.gen.a
McAfeeDownloader-BZH.gen.a
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Obfuscated.Win32.97466
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0056f1231 )
BitDefenderGen:Variant.Mikey.116104
K7GWTrojan ( 0056f1231 )
Cybereasonmalicious.e7f17e
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.OCR
APEXMalicious
KasperskyVirus.Win32.Renamer.e
AlibabaTrojanDownloader:Win32/Renamer.5f2578d9
NANO-AntivirusTrojan.Win32.Renamer.llnjs
ViRobotTrojan.Win.Z.Mikey.4434336.BW
RisingTrojan.Generic@AI.92 (RDML:HQ8eM82HX6V27q9Uhimncg)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Siggen16.29485
VIPREGen:Variant.Mikey.116104
TrendMicroTROJ_GEN.R002C0DJS23
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Mikey.116104 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=89)
GoogleDetected
AviraTR/Crypt.XPACK.Gen3
VaristW32/Unruy.F.gen!Eldorado
MicrosoftTrojanDownloader:Win32/Unruy.I
XcitiumTrojWare.Win32.Obfuscated.mrj@4sah5j
ArcabitTrojan.Mikey.D1C588
ZoneAlarmVirus.Win32.Renamer.e
GDataWin32.Trojan.PSE.1Q4TWXK
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Banito.C1717
Acronissuspicious
BitDefenderThetaAI:Packer.0B641E211F
ALYacGen:Variant.Mikey.116104
DeepInstinctMALICIOUS
VBA32BScope.Trojan.TE.01527
Cylanceunsafe
PandaTrj/Chgt.AC
TrendMicro-HouseCallTROJ_GEN.R002C0DJS23
TencentVirus.Win32.Renamer.a
IkarusBackdoor.Win32.Banito
MaxSecureVirus.W32.Renamer.E
FortinetW32/Renamer.E
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent.OCR?

Win32/Agent.OCR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment