Spy

Win32/Spy.Agent.OZT removal instruction

Malware Removal

The Win32/Spy.Agent.OZT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.OZT virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Terminates another process
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup

How to determine Win32/Spy.Agent.OZT?


File Info:

name: F2047C7A66BD4DD95AF1.mlw
path: /opt/CAPEv2/storage/binaries/a7a4e4ee893fa02b7c3eb808f1bd13782f267a1df35466bd10fc46f06d6ba9bb
crc32: C984FA3C
md5: f2047c7a66bd4dd95af12dde01c0e31b
sha1: 1990fa48702c52688ce6da05b714a1b3e634db76
sha256: a7a4e4ee893fa02b7c3eb808f1bd13782f267a1df35466bd10fc46f06d6ba9bb
sha512: 8932157acf60dabb54e9dbb205cd04fbba7e82a51f6fdc228e124b0d13627dc3a69ac49e2c20b034d81c56720210a35ae77a87ef815ce9beba5442227443d458
ssdeep: 1536:UMhD11v7xtlC2UKaI4LWLGKiP739l+M4jHT5Yw2HMVW:Us7HCXCoWLosMWT5YzCW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D938D16B980C072D056197644A9DBB29B3DB8322B78D9D3F7810B6E5F212D35A3B34F
sha3_384: 49a69be46f30a15ac91882587f1df546aa13bd9cc1a878f1d0a23a7cc543664fea3933fe69e8b48accf5361ac8a0a981
ep_bytes: e839670000e979feffff8bff558bec81
timestamp: 2014-12-02 05:38:30

Version Info:

FileDescription: Host Process for Windows Services
FileVersion: 6. 1. 7600. 16385
LegalCopyright: Copyright © Microsoft Corporation. All rights reserv...
OriginalFilename: svchsrv.exe
ProductName: Microsoft®Windows® Operating System
ProductVersion: 6, 1, 7600, 16385
Translation: 0x0409 0x04b0

Win32/Spy.Agent.OZT also known as:

LionicTrojan.Win32.Dinwod.4!c
CylanceUnsafe
ZillyaDropper.Dinwod.Win32.1212
SangforTrojan.Win32.Bitter.uyyg
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDropper:Win32/Dinwod.494a75fc
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34806.fu1@aevU1Cmi
CyrenW32/Trojan.VMVD-4595
SymantecTrojan.Gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Agent.OZT
TrendMicro-HouseCallBKDR_BITRET.A
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Dinwod.tzk
AvastWin32:Numeriq-A [Wrm]
RisingSpyware.Agent!8.C6 (CLOUD)
TrendMicroBKDR_BITRET.A
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Dinwod
JiangminTrojanDropper.Dinwod.nc
Antiy-AVLTrojan[Dropper]/Win32.Dinwod
KingsoftWin32.Troj.Dinwod.t.(kcloud)
MicrosoftTrojan:Win32/Occamy.CA7
ZoneAlarmTrojan-Dropper.Win32.Dinwod.tzk
AhnLab-V3Dropper/Win32.Daws.R193622
McAfeeArtemis!F2047C7A66BD
VBA32BScope.TrojanDropper.Dinwod
MalwarebytesGeneric.Malware/Suspicious
TencentWin32.Trojan.Falsesign.Dyzc
YandexTrojan.GenAsa!Y4TRaBhj40Q
MAXmalware (ai score=99)
MaxSecureTrojan.Malware.7894719.susgen
FortinetW32/Dinwod.TZK!tr
AVGWin32:Numeriq-A [Wrm]
PandaTrj/CI.A

How to remove Win32/Spy.Agent.OZT?

Win32/Spy.Agent.OZT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment