Malware

Win32/Agent.OKR removal instruction

Malware Removal

The Win32/Agent.OKR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.OKR virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent.OKR?


File Info:

name: 33A8A4BCC9AA908CF04F.mlw
path: /opt/CAPEv2/storage/binaries/0345d9007d33e43e764d076d6115f7bea5b0a52f02bffa5c5d62f73f06603df9
crc32: 0929ADF1
md5: 33a8a4bcc9aa908cf04f795e341bdaae
sha1: e1080551f4dcebbfeaccb8c9e7174e3931069fc8
sha256: 0345d9007d33e43e764d076d6115f7bea5b0a52f02bffa5c5d62f73f06603df9
sha512: 8d67867f4e526f95cd149574fa5faf9daeaf76dcafd20184f7d9cc84bcfa5d55d99344ff71adfba8866d4a079abe4dbc554a22e35cb6d7fe3bc793bd55bbbe2a
ssdeep: 768:CIIIWV2IlKTIIIIIIIIIILVI6db/bh2KXFdU/6+XF/3etVgk8RBBjPRXzeE2Dx43:EJ+XB/bgKX8BF/3S2k6Bc3KmHiUMl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12133D058213DDE8EF586FA3512657CE3EC645C8D49C4FA138C88677BC2C5A984D8FB82
sha3_384: 5b82d05fa5a56c02873dc54d33108f768f6274561de708deefff28b4fe358606f535e3e477cf6267589fcc95a487b455
ep_bytes: 64a130000000e8000000005afc6633d2
timestamp: 2011-01-29 20:49:26

Version Info:

0: [No Data]

Win32/Agent.OKR also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.47122
FireEyeGeneric.mg.33a8a4bcc9aa908c
ALYacGen:Variant.Midie.47122
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00060e4c1 )
AlibabaTrojan:Win32/Inject.ac6e1f13
K7GWTrojan ( 00060e4c1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.438FADF01E
CyrenW32/Cosmu.K.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.OKR
TrendMicro-HouseCallTROJ_KRYPTK.SM10
ClamAVWin.Malware.Midie-9936226-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Midie.47122
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Agent-AMRX [Trj]
TencentWin32.Trojan.Generic.Ljue
Ad-AwareGen:Variant.Midie.47122
EmsisoftGen:Variant.Midie.47122 (B)
TrendMicroTROJ_KRYPTK.SM10
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.qc
SophosML/PE-A + Mal/Inject-CG
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.3513697
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Midie.53760.BX
GDataGen:Variant.Midie.47122
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Gampass.R467614
Acronissuspicious
McAfeeGenericRXAA-AA!33A8A4BCC9AA
VBA32Malware-Cryptor.Win32.General.4
MalwarebytesMalware.AI.3766743511
APEXMalicious
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazrfTIzkrbTJg9ycnhElsV6F)
YandexTrojan.GenAsa!g4uRYh33TJE
IkarusTrojan.Win32.Cosmu
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cosmu.AO!tr
AVGWin32:Agent-AMRX [Trj]
Cybereasonmalicious.cc9aa9
PandaTrj/Genetic.gen

How to remove Win32/Agent.OKR?

Win32/Agent.OKR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment