Rootkit

Win32/Rootkit.Agent.OBZ (file analysis)

Malware Removal

The Win32/Rootkit.Agent.OBZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Rootkit.Agent.OBZ virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine Win32/Rootkit.Agent.OBZ?


File Info:

crc32: 1692B4C8
md5: 4101c0156c22dc3129c0ab29d4972dd6
name: tmpszzaw9v0
sha1: 2a8e53e714215683afb4679806348a1d7de6ea09
sha256: 0527cadcccd568937cd8c518f3e11420a7d5686539ba4e9491969be7a614ba00
sha512: 46df1cf4d0033df68dd1a73032766d1fa3846385701e3a54bfa2a75c74b60f18ea94676eac4bcd0288f1f464415c538c3184dbd68444d04d3965b3399e5846e3
ssdeep: 24576:Twfq1owTtDZZmrt9Iy+J+hieTshGmBJtj2jz46Q6MHqwB4po7y:0otDuEbJ+RTsoG2jz46QFz4po7y
type: PE32 executable (native) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Rootkit.Agent.OBZ also known as:

BkavHW32.Packed.
DrWebTrojan.NtRootKit.20062
MicroWorld-eScanGen:Variant.Mikey.111105
FireEyeGeneric.mg.4101c0156c22dc31
Qihoo-360Generic/HEUR/QVM00.1.004D.Malware.Gen
McAfeeGenericRXEJ-JL!4101C0156C22
CylanceUnsafe
SangforMalware
K7AntiVirusRootKit ( 00559e8d1 )
BitDefenderGen:Variant.Mikey.111105
K7GWRootKit ( 00559e8d1 )
Cybereasonmalicious.56c22d
Invinceaheuristic
F-ProtW32/S-68f0e4b7!Eldorado
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Score-6856515-0
GDataGen:Variant.Mikey.111105
KasperskyHEUR:Trojan.Win32.Generic
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazo1pHpQnt/kvQoWJuIRxzvI)
Ad-AwareGen:Variant.Mikey.111105
SophosMal/VMProtBad-A
F-SecureTrojan.TR/Rootkit.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Variant.Mikey.111105 (B)
SentinelOneDFI – Malicious PE
CyrenW32/S-68f0e4b7!Eldorado
AviraTR/Rootkit.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Mikey.D1B201
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ditertag.A
Acronissuspicious
ALYacGen:Variant.Mikey.111105
MAXmalware (ai score=84)
ESET-NOD32a variant of Win32/Rootkit.Agent.OBZ
IkarusTrojan.Win32.Tiggre
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.OBZ!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Rootkit.Agent.OBZ?

Win32/Rootkit.Agent.OBZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment