Spy

Win32/Spy.Agent.OSD removal tips

Malware Removal

The Win32/Spy.Agent.OSD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.OSD virus can do?

  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (21 unique times)
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Sniffs keystrokes
  • Creates a hidden or system file

How to determine Win32/Spy.Agent.OSD?


File Info:

crc32: 76E2307B
md5: ab5d2fc551ab2fe0ecf387ef17fde91f
name: chattest.exe
sha1: 0f822f6bc5a8ebc0143d653126aca546d2482ad2
sha256: b2124136b60a89f5b9f89a722d27a5cf2d6f0c60ed82e9a1fe89b2605f30f0e3
sha512: 492de78f0a1334d829957014f6d02d9f14c02193d625774dbf2c0e5d8daec038467d1155fa2d96bfae84a46ab35ef87a48ce99575e76718be620837543f2568a
ssdeep: 6144:nL1ncfWwN0oc35jeRh8Xqfy/Ka1OHAH0tMrKCTEABG+Z9d3cQT/9nR4Ioy19G:nLdcfxaeM6fy/KaVUtgKkTZ73coNRJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Spy.Agent.OSD also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.WebPick.9115
MicroWorld-eScanGen:Variant.Downloader.212
CAT-QuickHealBackdoor.Dodiw.A5
McAfeeGenericRXAA-FA!AB5D2FC551AB
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Downloader.212
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.551ab2
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34152.wmGfaSaE66mi
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyTrojan-Spy.Win32.Larby.ix
NANO-AntivirusTrojan.Win32.Dodiw.duviir
RisingSpyware.Agent!1.AD22 (CLASSIC)
Ad-AwareGen:Variant.Downloader.212
ComodoTrojWare.Win32.TrojanDropper.Sysn.CH@5y3z3q
F-SecureHeuristic.HEUR/AGEN.1119873
TrendMicroBKDR_DODIW.SM
FortinetW32/Agent.OSD!tr
FireEyeGeneric.mg.ab5d2fc551ab2fe0
SophosTroj/Agent-BAGZ
IkarusBackdoor.Win32.Dodiw
JiangminTrojan/Generic.bhtfw
AviraHEUR/AGEN.1119873
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.Downloader.212
ZoneAlarmTrojan-Spy.Win32.Larby.ix
MicrosoftBackdoor:Win32/Dodiw.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dodiw.C1317390
Acronissuspicious
ALYacGen:Variant.Downloader.212
VBA32Trojan.WebPick
MalwarebytesBackdoor.Agent
PandaTrj/Genetic.gen
ESET-NOD32Win32/Spy.Agent.OSD
TrendMicro-HouseCallBKDR_DODIW.SM
YandexTrojanSpy.Agent!lGMj4upPDvg
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
GDataGen:Variant.Downloader.212
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM11.1.2BAC.Malware.Gen

How to remove Win32/Spy.Agent.OSD?

Win32/Spy.Agent.OSD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment