Malware

Should I remove “Win32/Agent.PPD”?

Malware Removal

The Win32/Agent.PPD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.PPD virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Korean
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Agent.PPD?


File Info:

crc32: 3AB4B03F
md5: 4e477b4138e648efe9f36272020c0a5d
name: 4E477B4138E648EFE9F36272020C0A5D.mlw
sha1: 94cafbf0c5cecce5edae837fa73887b4ead62fb9
sha256: 4febab61c7735722b233a6e8c4b825152e73049d6d229f470317cfdefa6728f1
sha512: ec4098fa3df80bd7eb7156c3a8bd834ba6ba197eb4d731beebcbfdf4824352aa3d5b7e579d1b6c9056ff52896ea91f0ade9fc02785a086de92d014cf8c8c3b68
ssdeep: 6144:y2I0RsxUuzOtlFf0BiqVM1fRRchNsyn3Vky:y2I0C6tl8inRRmZ3S
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Agent.PPD also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.11773
MicroWorld-eScanGen:Trojan.Heur.grZ@rvs4nHdOb
FireEyeGeneric.mg.4e477b4138e648ef
ALYacGen:Trojan.Heur.grZ@rvs4nHdOb
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Blocker.tqF4
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000ab46c1 )
BitDefenderGen:Trojan.Heur.grZ@rvs4nHdOb
K7GWTrojan ( 000ab46c1 )
Cybereasonmalicious.138e64
BitDefenderThetaAI:Packer.1E9A83B41D
SymantecTrojan.Gen.2
TotalDefenseWin32/FakeFLDR_i
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.hndz
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareGen:Trojan.Heur.grZ@rvs4nHdOb
SophosMal/Generic-R
ComodoMalware@#qglcgrlfgn1x
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Agent.Win32.370854
McAfee-GW-EditionGenericRXDR-CM!4E477B4138E6
EmsisoftGen:Trojan.Heur.grZ@rvs4nHdOb (B)
IkarusBackdoor.Win32.PcClient
JiangminTrojan/Generic.arhcy
MaxSecureVirus.Mabezat.Dam
AviraTR/Dropper.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Heur.E8C384
ZoneAlarmTrojan-Ransom.Win32.Blocker.hndz
GDataGen:Trojan.Heur.grZ@rvs4nHdOb
CynetMalicious (score: 100)
McAfeeGenericRXDR-CM!4E477B4138E6
VBA32Trojan-Ransom.Blocker
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Agent.PPD
TencentMalware.Win32.Gencirc.10b81e6b
YandexTrojan.GenAsa!+Nmet/dmpEI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.22960!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Ransom.aa3

How to remove Win32/Agent.PPD?

Win32/Agent.PPD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment