Spy

Win32/Spy.Agent.NET removal instruction

Malware Removal

The Win32/Spy.Agent.NET is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.NET virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Win32/Spy.Agent.NET?


File Info:

name: 0EFADE6825E49CF0CF9C.mlw
path: /opt/CAPEv2/storage/binaries/e1aac4d793083c571d64b61961eea2c54e3d003daa27ee9efdc88046acd73ae1
crc32: C2E0C744
md5: 0efade6825e49cf0cf9c87695d466157
sha1: 6ccf60a602b22540a5dca43264812fedf7c2d15f
sha256: e1aac4d793083c571d64b61961eea2c54e3d003daa27ee9efdc88046acd73ae1
sha512: fd4ec4c5bcba43f8c27f80b3f53b6b7d164e8a35b5758370c0d5e2a30190189ffd74e895360244afe37d94a2af3f2565bf1bd80583c32c3909d078575148c9c1
ssdeep: 1536:StTR5QAdTzahnkhZCsdeiiJAcV72PAHRlXoUa:uRR9oaUoYJAWWUa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E433E1767DDABE71D33544BE7C5AE0E2629B98916F02020E35E905F34C0BB804E2CB5E
sha3_384: 5e56d3cd5ef5450392ee95e6f527aeadb9611d3c2f4b18c50e56c02c35f803430b061a8b367d5248c72d26a58186ee81
ep_bytes: 558bec83c4f0b8a4274000e8ecf0ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Agent.NET also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Rbot.leZz
CynetMalicious (score: 100)
FireEyeGeneric.mg.0efade6825e49cf0
SkyhighBehavesLike.Win32.Eggnog.qc
McAfeeSpy-Agent.jh.dr
Cylanceunsafe
ZillyaBackdoor.CPEX.Win32.25500
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00024c9d1 )
AlibabaVirTool:Win32/DelfInject.04326821
K7GWTrojan ( 00024c9d1 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Generic.AEO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.NET
APEXMalicious
ClamAVWin.Trojan.Dropper-5425
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Inject.2
NANO-AntivirusTrojan.Win32.Delphi.cnwqpa
MicroWorld-eScanGen:Variant.Inject.2
AvastWin32:Zbot-DA [Trj]
SophosMal/Dropper-T
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.DownLoader.22816
VIPREGen:Variant.Inject.2
TrendMicroTSPY_DISKEN.D
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Inject.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.FriJoiner.yp
GoogleDetected
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
MicrosoftVirTool:Win32/DelfInject.gen!AC
XcitiumTrojWare.Win32.PSW.LdPinch.~W1@18pm5y
ArcabitTrojan.Inject.2
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Inject.2
VaristW32/Backdoor.AC.gen!Eldorado
AhnLab-V3Worm/Win32.IRCBot.R2114
BitDefenderThetaAI:Packer.C8D19F2B1E
ALYacGen:Variant.Inject.2
MAXmalware (ai score=100)
VBA32Malware-Cryptor.Inject.gen
MalwarebytesMalware.AI.3673602413
PandaTrj/Sinowal.gen
TrendMicro-HouseCallTSPY_DISKEN.D
RisingMalware.Undefined!8.C (TFE:3:wIlGggpyyaF)
YandexTrojan.GenAsa!eejdqRnvbXw
IkarusVirus.Win32.DelfInject
FortinetW32/Zbot.BM!tr
AVGWin32:Zbot-DA [Trj]
Cybereasonmalicious.825e49
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Inject

How to remove Win32/Spy.Agent.NET?

Win32/Spy.Agent.NET removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment