Malware

Win32/Agent.ONS removal guide

Malware Removal

The Win32/Agent.ONS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ONS virus can do?

  • Authenticode signature is invalid

How to determine Win32/Agent.ONS?


File Info:

name: F1AC55C0B119E9CB6F72.mlw
path: /opt/CAPEv2/storage/binaries/d9260b7ab7d59537d6d07bd48188d4a1e17e42422841bfd9697ed266ec04c08f
crc32: 52B12652
md5: f1ac55c0b119e9cb6f72049c2fe824bb
sha1: 9a869edf26bda6f10dae7744f0f7cc85c363e71b
sha256: d9260b7ab7d59537d6d07bd48188d4a1e17e42422841bfd9697ed266ec04c08f
sha512: 569abfa369fa5f52ac89add6f3fd8adae5c0dca9c73c15ccc243fb541239bb5fafd37a2463ee21edba438023716dc38fc372334fdebffce2e46bf6fe2411786c
ssdeep: 384:bkzfevUQBYvTtHJQYQBoUBUHfNxEhpm56OovKSbBqHFRaOhWbN3QW:bkyhYrtpQYQBfBU/epm5yzqXalN3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196037DE392B815B7FFF2077C0E22CA0D4CF6B7556EAAE02971AC10190D7A4D24E11E1B
sha3_384: bae4fcd2d98edec5353e476b8d4a19a18c56792ae210b47a7d120c0b521ec6198e00ed4685f9e44de34bd7ecac4afdd5
ep_bytes: 558bec6aff68a071400068a03b400064
timestamp: 2011-07-17 16:29:28

Version Info:

Comments:
CompanyName: Microsoft Corporation
FileDescription: RndSeed
FileVersion: 0, 27, 0, 83
InternalName: rndseed
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: RndSeed.exe
PrivateBuild:
ProductName: Microsoft® Windows® Operating System
ProductVersion: 0, 27, 0, 83
SpecialBuild:
Translation: 0x0409 0x04b0

Win32/Agent.ONS also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Rndseed.5
MicroWorld-eScanTrojan.Peed.Gen
FireEyeGeneric.mg.f1ac55c0b119e9cb
ALYacTrojan.Peed.Gen
CylanceUnsafe
VIPRETrojan.Peed.Gen
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004ee7ba1 )
K7GWTrojan ( 004ee7ba1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34606.cq0@a4t1MLpi
VirITTrojan.Win32.Generic.BYAC
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ONS
APEXMalicious
ClamAVWin.Trojan.Peed-1027
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Peed.Gen
AvastWin32:Trojan-gen
Ad-AwareTrojan.Peed.Gen
EmsisoftTrojan.Peed.Gen (B)
F-SecureHeuristic.HEUR/AGEN.1230642
McAfee-GW-EditionBehavesLike.Win32.BadFile.pt
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.ogkf
GoogleDetected
AviraHEUR/AGEN.1230642
Antiy-AVLTrojan/Generic.ASMalwS.2779
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Peed.Gen
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C110988
McAfeeArtemis!F1AC55C0B119
MAXmalware (ai score=89)
VBA32Trojan.Rnds
RisingMalware.Undefined!8.C (TFE:5:zcuf7Oi7y6H)
YandexTrojan.GenAsa!UlJarm79jbQ
TACHYONTrojan/W32.Rnds.40960.B
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ONS!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.0b119e
PandaGeneric Malware

How to remove Win32/Agent.ONS?

Win32/Agent.ONS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment