Malware

Win32/Agent.OHU removal instruction

Malware Removal

The Win32/Agent.OHU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.OHU virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Agent.OHU?


File Info:

name: 7357A59FA9E4A13D5384.mlw
path: /opt/CAPEv2/storage/binaries/082653d2d5355b9bde2351dc38f36d73f754bd32b8f727096943a4132c904afb
crc32: 373167D4
md5: 7357a59fa9e4a13d53842deb535d70d7
sha1: 0b543b0128b6720f46ac7a2db5eb39ea08746bf2
sha256: 082653d2d5355b9bde2351dc38f36d73f754bd32b8f727096943a4132c904afb
sha512: 4a6c33321d1c80e88af747f3224ba525916078c08b275194f144ebec1ad322267a08d52f76ee35a6213bb12c2cfcb96e4cda894ef59dc0152e2640845d357649
ssdeep: 3072:Z3jLOESK7aHTfaP6xBX/iU9Xni1xSMtn39:Z3jymi1x5/X9XiOeN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EFE38EC87F155C9BDC0A223D3C73EAC49E6AA8117AC6C14B647E33DFC59A1D82552B32
sha3_384: ddbc27c3ad2057fcee91b84bbb564ce4e9b715c0a77cadf425f0d98785b5c44f3a9c28672b4c1410ea619f803eede246
ep_bytes: 558bec515753bf00104000b930200100
timestamp: 2009-01-19 09:34:39

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Update Package
FileVersion: 1, 0, 0, 689
InternalName: SFXCAB.EXE
LegalCopyright: ? Microsoft Corporation. All rights reserved.
OriginalFilename: SFXCAB.EXE
ProductName: Windows XP Family
ProductVersion: 5, 5, 33, 689
Translation: 0x0804 0x04b0

Win32/Agent.OHU also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Downloader.18
FireEyeGeneric.mg.7357a59fa9e4a13d
McAfeeGenericRXHM-HT!7357A59FA9E4
VIPREGen:Variant.Downloader.18
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Downloader.18
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fa9e4a
CyrenW32/Agent.HA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.OHU
APEXMalicious
AvastWin32:AutoRun-ARB [Wrm]
KasperskyHEUR:Worm.Win32.Generic
NANO-AntivirusTrojan.Win32.TrjGen.ddbfpa
CynetMalicious (score: 100)
RisingPacker.Win32.Agent.bs (CLASSIC)
Ad-AwareGen:Variant.Downloader.18
SophosML/PE-A + Mal/EncPk-ZL
ComodoWorm.Win32.Autorun.1438970@1n9lsa
DrWebBackDoor.Siggen.48315
ZillyaBackdoor.Agent.Win32.8169
McAfee-GW-EditionBehavesLike.Win32.Dropper.cm
EmsisoftGen:Variant.Downloader.18 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdware/Downloader.dp
WebrootW32.Dynamer.Gen
AviraWORM/Autorun.143897
Antiy-AVLTrojan/Generic.ASMalwFH.3307
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Downloader.18
GoogleDetected
Acronissuspicious
VBA32BScope.Trojan.Dorv
ALYacGen:Variant.Downloader.18
CylanceUnsafe
PandaTrj/CI.A
TencentMalware.Win32.Gencirc.10b8f3b4
YandexTrojan.GenAsa!ohRIJNlgyGk
MAXmalware (ai score=89)
FortinetW32/Agent.IUA!tr.bdr
AVGWin32:AutoRun-ARB [Wrm]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent.OHU?

Win32/Agent.OHU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment