Malware

Win32/Agent_AGen.DDZ removal instruction

Malware Removal

The Win32/Agent_AGen.DDZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.DDZ virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.DDZ?


File Info:

name: CA856E773B62F74FEF62.mlw
path: /opt/CAPEv2/storage/binaries/8953f9e6d33dc538c005dd7ff8d029d6a46768f81787a7aa1c4eee5c8291e107
crc32: FFCD5901
md5: ca856e773b62f74fef626914d4f83acc
sha1: d2125c715decd5313be99cd27dbaaad1137e5d63
sha256: 8953f9e6d33dc538c005dd7ff8d029d6a46768f81787a7aa1c4eee5c8291e107
sha512: 0eff073410f91ded45ba0e3699e7f38fa55c15983b85f7cffd64f5a4a8d494f133c8f0e5a81ae4b33cee57e1398f28e7ae2ef7ee485d253c26e59cc1d2172fdd
ssdeep: 384:XyNfzZlPPecZKktClrq9mPeuaBU3losjuzZ6UwYRGZq87PwtnvtdGZkK3HJxRC:8fzZ9Okt0fPP3lLuzZPKqUyjG6K3pxRC
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D5E2D9997E444CEBD9606338D0E7C7762A7CF151CA230B62F650E7348B337A1615B26E
sha3_384: 3ccac02b267076373a9aaae92ad84d219e5faa9db374ebd100902964ffe5d11ac464171584036b88fdc22f8a2f9a476d
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 05:42:24

Version Info:

0: [No Data]

Win32/Agent_AGen.DDZ also known as:

LionicTrojan.Win32.Fsysna.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.71610061
SkyhighBehavesLike.Win32.Injector.nm
McAfeeGenericRXWN-OS!CA856E773B62
VIPRETrojan.GenericKD.71610061
SangforTrojan.Win32.Agent.Vepn
K7AntiVirusTrojan ( 005b1a3b1 )
AlibabaTrojan:Win32/Fsysna.2016b990
K7GWTrojan ( 005b1a3b1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36744.c46@a4@Aj1i
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.DDZ
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Fsysna.jfnw
BitDefenderTrojan.GenericKD.71610061
AvastWin32:MalwareX-gen [Trj]
RisingTrojan.Agent!8.B1E (TFE:5:npQTbB3HsZR)
EmsisoftTrojan.GenericKD.71610061 (B)
F-SecureTrojan.TR/Dropper.Gen
FireEyeTrojan.GenericKD.71610061
SophosMal/Generic-S
GDataTrojan.GenericKD.71610061
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Fsysna
ArcabitTrojan.Generic.D444AECD
ZoneAlarmTrojan.Win32.Fsysna.jfnw
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R634466
Cylanceunsafe
PandaTrj/Chgt.AD
TencentWin32.Trojan.Fsysna.Najl
IkarusTrojan.Win32.Agent
FortinetW32/Agent_AGen.DDZ!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Agent_AGen.DDZ?

Win32/Agent_AGen.DDZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment