Malware

About “Win32/Agent.VAZ” infection

Malware Removal

The Win32/Agent.VAZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.VAZ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Transacted Hollowing
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Agent.VAZ?


File Info:

name: 9589497ECDF782102515.mlw
path: /opt/CAPEv2/storage/binaries/56604ca2b5291e067a16d62ad9f45acc11c14b77f799de40ff82cc6ba156055a
crc32: 62D190E6
md5: 9589497ecdf782102515421f9d487904
sha1: 655d7b5f4ba2474ee611d02df2d05dc3a219251a
sha256: 56604ca2b5291e067a16d62ad9f45acc11c14b77f799de40ff82cc6ba156055a
sha512: a749c5b5cb447444dd5cb33ccdb068b563a788fcc2d7445ac59d2e50bdee205f12c8561646afa87df90c915ff81ae3206ea510ad5e7e3c2110b6a0e4c6a3d3dc
ssdeep: 12288:i5TpNMSFge0Wieq2cS3qMebx+nOkqV7hV+hgj0TiqqLufY/f11owzIRqci0oM7bn:iDNMSR8tH+viLufY/f1uRv7hkQAH2XGm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FF4BF61BD8180B3E2A110B565B9EB370E3CA9244711A9D3E3C05E7C9D316E1AF3B75D
sha3_384: b796e06d3919a2622a0b6907f1496d9e2352d3716451941e34eca8dd15349d7fd3f477ae5658990ffc69f19690977cc5
ep_bytes: e8c80a0000e974feffffe9eecf0000e9
timestamp: 2022-04-24 14:09:10

Version Info:

0: [No Data]

Win32/Agent.VAZ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.VAZ
APEXMalicious
KasperskyVHO:Trojan-Banker.Win32.ClipBanker.gen
F-SecureHeuristic.HEUR/AGEN.1237910
BitDefenderThetaGen:NN.ZexaF.34606.VuW@aql0@vmi
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
FireEyeGeneric.mg.9589497ecdf78210
SophosGeneric ML PUA (PUA)
AviraHEUR/AGEN.1237910
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.C5100471
Acronissuspicious
RisingTrojan.Generic@AI.83 (RDMK:cmRtazpz2q2mL/mAZ2FF6c3k2SqE)
SentinelOneStatic AI – Malicious PE
Cybereasonmalicious.f4ba24

How to remove Win32/Agent.VAZ?

Win32/Agent.VAZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment