Spy

Should I remove “Win32/Spy.Agent.OPC”?

Malware Removal

The Win32/Spy.Agent.OPC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.OPC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Deletes its original binary from disk
  • Likely virus infection of existing system binary

How to determine Win32/Spy.Agent.OPC?


File Info:

name: 437F434DE3FE52800831.mlw
path: /opt/CAPEv2/storage/binaries/34eecd06ef4b717439eb9ae87a02fa5301c6d6a8f38f9cdafa6a1d086b5621ef
crc32: E03F98CD
md5: 437f434de3fe52800831e4e3e2f8d0a6
sha1: 167a81b203d09d0cef9a07205ab7e0b6f7715e9b
sha256: 34eecd06ef4b717439eb9ae87a02fa5301c6d6a8f38f9cdafa6a1d086b5621ef
sha512: fd72d6ba743cfd2d473975fb58eeb0416b00bd1e868f393c0e18836f957cbd58986cca308c10433a8aaad1bb4bb40c00ec25d6144ca0bada58b89f5ce2603c02
ssdeep: 12288:SC2D7ezCllrldTRzZ1HFgVAxXxeq71d31ELvP:SC+iCxdTv1HFgVAxXxeq71h1ET
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15625E8626502973BF508AE73C39FB73478206ECA1DE1465EF60EBB2857341F14E76289
sha3_384: 09855c2bbc2f02bbb091657a08c9f7d605b63bd026212b871af43b558d9eaead462f8023d262a1abfcdfce05616cc47a
ep_bytes: 558bec6aff68d0c14000685080400064
timestamp: 2011-03-26 05:35:14

Version Info:

0: [No Data]

Win32/Spy.Agent.OPC also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.386275
FireEyeGeneric.mg.437f434de3fe5280
McAfeeGenericRXAA-AA!437F434DE3FE
CylanceUnsafe
ZillyaTrojan.Agent.Win32.233308
K7AntiVirusSpyware ( 0055e3db1 )
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.de3fe5
CyrenW32/Agent.CHY.gen!Eldorado
ESET-NOD32a variant of Win32/Spy.Agent.OPC
APEXMalicious
ClamAVWin.Trojan.6601069-1
KasperskyTrojan-Spy.Win32.Agent.jxrh
BitDefenderGen:Variant.Zusy.386275
NANO-AntivirusTrojan.Win32.TrjGen.boescz
AvastWin32:Malware-gen
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazoMnxVaF/DQd+pmPS+q6LRL)
Ad-AwareGen:Variant.Zusy.386275
DrWebTrojan.PWS.Bonque.44
EmsisoftGen:Variant.Zusy.386275 (B)
JiangminTrojan.Generic.aroj
AviraHEUR/AGEN.1107121
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.710072
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.386275
CynetMalicious (score: 99)
VBA32Backdoor.MSIL.IRCBot
ALYacGen:Variant.Zusy.386275
MalwarebytesMalware.AI.1668748915
TencentMalware.Win32.Gencirc.10b28485
YandexTrojan.GenAsa!XR2/quIb0Jw
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.22793F
BitDefenderThetaGen:NN.ZexaE.34294.9qW@aKMxAObO
AVGWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Spy.Agent.OPC?

Win32/Spy.Agent.OPC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment