Spy

Win32/Spy.Agent.OBG removal tips

Malware Removal

The Win32/Spy.Agent.OBG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.OBG virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

wpad.local-net

How to determine Win32/Spy.Agent.OBG?


File Info:

name: E57982EE1ACEEABFEBC3.mlw
path: /opt/CAPEv2/storage/binaries/80af7c5bd89420704169ec97913fc5503dc5ccfb83c07de51fde7c5bc6dbdeec
crc32: 912D29F3
md5: e57982ee1aceeabfebc3ccd265d92839
sha1: 673a97bbcbb1b9121881da159cdcd254b02f697b
sha256: 80af7c5bd89420704169ec97913fc5503dc5ccfb83c07de51fde7c5bc6dbdeec
sha512: 4f4fe0be1ba339286157e02cf4b7c56eefb67662ce8b171ebda1e3e74b49b8738e5058e9bfaa5bc2dcb39c97bcfee846e9c2b7ca46a7fa1b704bf6c6b8d58059
ssdeep: 1536:ZcO1MlEBkuXfCw4xvoatUcnbhWsVn5TKJGAQJ00+6DGZC8Ls/ynCjuIEysTkASdH:11dfUvoa3bhWsl5TZn4yY3gDloCd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D343B10E522C43BF49245BEC6E647F9EABC99332F4A20DFC3E0A9DD93660D1743195A
sha3_384: 584fd67690f675ec40bca578723ca83960ea79a37b1482cfba6e0be80a7c5f98f5f8c7ca4e5029dbcbd9ad84c1582618
ep_bytes: 558bec6aff68c0fc42006884e7400064
timestamp: 2012-07-29 13:52:23

Version Info:

0: [No Data]

Win32/Spy.Agent.OBG also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Heur.Mint.Zard.30
CylanceUnsafe
Cybereasonmalicious.e1acee
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.OBG
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.30
NANO-AntivirusTrojan.Win32.TrjGen.bocpnf
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.dixl
Ad-AwareGen:Heur.Mint.Zard.30
SophosMal/Generic-L
ComodoMalware@#1i0p3roj8oi3u
DrWebTrojan.Siggen4.13716
VIPREBehavesLike.Win32.Malware.eah (mx-v)
McAfee-GW-EditionBehavesLike.Win32.Rootkit.dt
FireEyeGeneric.mg.e57982ee1aceeabf
EmsisoftGen:Heur.Mint.Zard.30 (B)
GDataGen:Heur.Mint.Zard.30
JiangminTrojan/Generic.ahgvv
WebrootW32.Trojan.Gen
AviraTR/Rogue.8131546
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Mint.Zard.30
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!E57982EE1ACE
MAXmalware (ai score=88)
VBA32BScope.TrojanPSW.Conquer
FortinetW32/Agent.OBG!tr.spy
BitDefenderThetaGen:NN.ZexaF.34294.oyX@a48H5ag
AVGWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Spy.Agent.OBG?

Win32/Spy.Agent.OBG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment