Malware

Win32/Agent.OGZ removal guide

Malware Removal

The Win32/Agent.OGZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.OGZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a registry key
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Agent.OGZ?


File Info:

crc32: 2CA26B77
md5: 6e6efbb499fae8cddba1381d4562bd17
name: 6E6EFBB499FAE8CDDBA1381D4562BD17.mlw
sha1: c01464d15dc40612ea0cf1411091bc906407994d
sha256: dc2288c45031e11837cf05346ef1aa8448a7ccc346c80cfd7a0a6164edc4475f
sha512: 7e86e8c0d580debdc60bbaec2dec761fce21df18b7332ea10ae7bf8f3464592a86b86999ebb9bf5d6c775dcbb4f5e221c4290c2be575181a30a5c4945cbe9e17
ssdeep: 1536:HbyBf/SXqK5QPqfhVWbdsmA+RjPFLC+e5h20ZGUGf2g:H7XqNPqfcxA+HFsh2Og
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Agent.OGZ also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.FileInfector.eGW@a0SquDf
FireEyeGeneric.mg.6e6efbb499fae8cd
CAT-QuickHealTrojan.Antavmu.D7
ALYacGen:Trojan.FileInfector.eGW@a0SquDf
CylanceUnsafe
VIPRETrojan.Win32.Antavmu.d (v)
AegisLabVirus.DOS.Moctezuma.tnBC
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Trojan.FileInfector.eGW@a0SquDf
K7GWTrojan ( 001f4e2b1 )
K7AntiVirusTrojan ( 001f4e2b1 )
BitDefenderThetaAI:Packer.A86A0CF01E
CyrenW32/Ildirim.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.OGZ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Antavmu-523
KasperskyVirus.DOS.Moctezuma.2416
AlibabaWorm:Win32/Antavmu.08ae247e
NANO-AntivirusTrojan.Win32.Antavmu.dhwgp
ViRobotTrojan.Win32.A.Antavmu.74752
RisingTrojan.Win32.Antavmu.b (CLASSIC)
Ad-AwareGen:Trojan.FileInfector.eGW@a0SquDf
TACHYONWorm/W32.FileInfector.74752
EmsisoftGen:Trojan.FileInfector.eGW@a0SquDf (B)
ComodoTrojWare.Win32.KillFiles.NEH@4qfvz0
F-SecureTrojan.TR/Antavmu.doena
DrWebTrojan.Siggen8.42052
ZillyaTrojan.KillFilesGen.Win32.1
TrendMicroTSPY_ANTAVMU_BK08301E.TOMC
McAfee-GW-EditionDropper-FAH!6E6EFBB499FA
SophosML/PE-A + Mal/Antavmu-A
SentinelOneStatic AI – Malicious PE – Downloader
JiangminTrojan.Antavmu.chz
WebrootW32.Trojan.Gen
AviraTR/Antavmu.doena
Antiy-AVLRiskWare[RiskTool]/Win32.Killfiles.neh
MicrosoftTrojan:Win32/Antavmu.D
ArcabitTrojan.FileInfector.E09A77
SUPERAntiSpywareWorm.Antavmu
AhnLab-V3Trojan/Win32.Antavmu.R25058
ZoneAlarmVirus.DOS.Moctezuma.2416
GDataGen:Trojan.FileInfector.eGW@a0SquDf
CynetMalicious (score: 100)
TotalDefenseWin32/Antavmu.HM
Acronissuspicious
McAfeeDropper-FAH!6E6EFBB499FA
MAXmalware (ai score=85)
VBA32BScope.Trojan.Downloader
MalwarebytesVirus.Injector
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ANTAVMU_BK08301E.TOMC
TencentTrojan.Win32.Agent.mgr
YandexTrojan.GenAsa!mLg/yf6hjK0
IkarusBackdoor.Poison
FortinetW32/Antavmu.JWS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Antavmu.A

How to remove Win32/Agent.OGZ?

Win32/Agent.OGZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment