Malware

How to remove “Win32/Agent.UY”?

Malware Removal

The Win32/Agent.UY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.UY virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Agent.UY?


File Info:

name: CC9297ECDE183CCE7846.mlw
path: /opt/CAPEv2/storage/binaries/f7357fa5c3c5698e8d6fa716de0e6c492cf381773c5f3c699cb6a293fb982f56
crc32: 552C1537
md5: cc9297ecde183cce7846fe60128b86af
sha1: 2cf392390d1c21979af65d4ce9b082dc5eb0c75f
sha256: f7357fa5c3c5698e8d6fa716de0e6c492cf381773c5f3c699cb6a293fb982f56
sha512: 0f19ab8398f6094712783cb40ddec3eb702a38edb0ec4645c75910b65eb4633cf32018942597e64f2d4a5694e2c8b79ee791571558fa8d3175da6d67479ef0f5
ssdeep: 6144:XY4N0qCFJKIwTCJhKSZI4zLVSVp9CoTSg:Ikr4KZaKSZhnVepYoTSg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B68493462E8CE130DE7016BF2CA906B96ED14BE9E22239C1D794D15F09DFB2409FF5A4
sha3_384: 7c8c0500834ead77d691ee349218fbf805d4c31933786d7db93d3d72680225779ca0c40d8cd51e49fae26cdbb8dbe072
ep_bytes: 6a00e821010100a3bc514100e81d0101
timestamp: 1998-09-03 23:04:52

Version Info:

0: [No Data]

Win32/Agent.UY also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Barys.2588
ClamAVWin.Trojan.Fugrafa-9733007-0
McAfeeGenericRXVQ-ZN!CC9297ECDE18
MalwarebytesGeneric.Trojan.Malicious.DDS
ZillyaBackdoor.Small.Win32.11061
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005110401 )
K7GWTrojan ( 005110401 )
Cybereasonmalicious.cde183
VirITTrojan.Win32.Click.DWD
CyrenW32/Agent.FRV.gen!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.UY
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Small.ml
BitDefenderGen:Variant.Barys.2588
NANO-AntivirusTrojan.Win32.Click.gacxgj
AvastWin32:Downloader-TH [Trj]
TencentBackdoor.Win32.Small.kc
EmsisoftGen:Variant.Barys.2588 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Click.2603
VIPREGen:Variant.Barys.2588
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.cc9297ecde183cce
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1620HTT
JiangminBackdoor.Small.ix
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan[Backdoor]/Win32.Small
XcitiumTrojWare.Win32.Agent.ve@4yoq0p
ArcabitTrojan.Barys.DA1C
ViRobotBackdoor.Win32.A.Small.80896
ZoneAlarmBackdoor.Win32.Small.ml
MicrosoftBackdoor:Win32/Small.IR
GoogleDetected
AhnLab-V3Backdoor/Win.Small.C5394046
BitDefenderThetaGen:NN.ZexaF.36196.w0Z@a4E5W6i
ALYacGen:Variant.Barys.2588
MAXmalware (ai score=87)
VBA32BScope.Backdoor.Small
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Small.hol (CLASSIC)
YandexBackdoor.Small!zCKL7a7XABY
IkarusBackdoor.Win32.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.U!tr
AVGWin32:Downloader-TH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Agent.UY?

Win32/Agent.UY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment