What is the Win32:Evo-gen [Trj] virus?
Written by Robert Bailey
Seeing the Win32/Spy.Agent.PRG detection usually means that your PC is in big danger. This virus can correctly be identified as ransomware – virus which ciphers your files and asks you to pay for their decryption. Deleteing it requires some unusual steps that must be taken as soon as possible.
GridinSoft Anti-Malware Review
It is better to prevent, than repair and repent!
When we talk about the intrusion of unfamiliar programs into your computer’s work, the proverb “Forewarned is forearmed” describes the situation as accurately as possible. Gridinsoft Anti-Malware is exactly the tool that is always useful to have in your armory: fast, efficient, up-to-date. It is appropriate to use it as an emergency help at the slightest suspicion of infection.
Gridinsoft Anti-Malware 6-day trial available.
EULA | Privacy Policy | 10% Off Coupon
Subscribe to our Telegram channel to be the first to know about news and our exclusive materials on information security.

Win32/Spy.Agent.PRG detection is a malware detection you can spectate in your system. It often appears after the preliminary procedures on your PC – opening the untrustworthy email, clicking the banner in the Internet or mounting the program from untrustworthy sources. From the moment it shows up, you have a short time to take action until it begins its malicious activity. And be sure – it is far better not to wait for these malicious actions.

What is Win32/Spy.Agent.PRG virus?

Win32/Spy.Agent.PRG is ransomware-type malware. It searches for the files on your disk drives, ciphers it, and then asks you to pay the ransom for receiving the decryption key. Besides making your files locked, this virus additionally does a ton of damage to your system. It changes the networking setups in order to avoid you from reading the elimination guidelines or downloading the antivirus. In rare cases, Win32/Spy.Agent.PRG can additionally prevent the launching of anti-malware programs.

Win32/Spy.Agent.PRG Summary

In total, Win32/Spy.Agent.PRG ransomware actions in the infected PC are next:

  • Behavioural detection: Executable code extraction – unpacking;
  • Yara rule detections observed from a process memory dump/dropped files/CAPE;
  • Creates RWX memory;
  • Possible date expiration check, exits too soon after checking local time;
  • Dynamic (imported) function loading detected;
  • CAPE extracted potentially suspicious content;
  • The binary contains an unknown PE section name indicative of packing;
  • Authenticode signature is invalid;
  • CAPE detected the CryptBot malware family;
  • Ciphering the documents kept on the victim’s disk drives — so the victim cannot use these files;
  • Blocking the launching of .exe files of anti-malware programs
  • Blocking the launching of installation files of anti-virus programs

Ransomware has been a nightmare for the last 4 years. It is challenging to imagine a more hazardous malware for both individual users and organizations. The algorithms used in Win32/Spy.Agent.PRG (usually, RHA-1028 or AES-256) are not hackable – with minor exclusions. To hack it with a brute force, you need to have a lot more time than our galaxy actually exists, and possibly will exist. But that virus does not do all these bad things immediately – it can take up to a few hours to cipher all of your documents. Therefore, seeing the Win32/Spy.Agent.PRG detection is a clear signal that you should begin the removal process.

Where did I get the Win32/Spy.Agent.PRG?

Usual methods of Win32/Spy.Agent.PRG distribution are basic for all other ransomware variants. Those are one-day landing sites where victims are offered to download and install the free program, so-called bait e-mails and hacktools. Bait e-mails are a relatively modern strategy in malware distribution – you receive the email that imitates some standard notifications about shippings or bank service conditions changes. Inside of the email, there is an infected MS Office file, or a link which leads to the exploit landing site.

Malicious email spam

Malicious email message. This one tricks you to open the phishing website.

Avoiding it looks quite uncomplicated, but still demands tons of awareness. Malware can hide in different spots, and it is better to stop it even before it gets into your system than to trust in an anti-malware program. General cybersecurity awareness is just an essential item in the modern-day world, even if your relationship with a computer stays on YouTube videos. That may save you a lot of money and time which you would spend while looking for a fixing guide.

Win32/Spy.Agent.PRG malware technical details

File Info:

name: EF7230FCDB9B56D6C0DA.mlw
path: /opt/CAPEv2/storage/binaries/b1de9060bb0800f5ff6a1cbfea408becd1bfdc2eb46752a05261854b6daa2c94
crc32: 6D465D99
md5: ef7230fcdb9b56d6c0dac55278535b8e
sha1: 805a2c86fee7666979f1466476851a10c68c01c5
sha256: b1de9060bb0800f5ff6a1cbfea408becd1bfdc2eb46752a05261854b6daa2c94
sha512: 3902682feb866b2f4db13901fad5be1338dbc6b5a822334f9f142c2d58bc3b29be312e9fffad86a8e94581a9f9dc3366520af3bb194962beaf35b0e14bdc9202
ssdeep: 12288:R3CW0L01afS3CW0L01afS3CW0L01af5hRMt:R3CW0YYq3CW0YYq3CW0YYDRe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F94E0A2A3FD2856F5F71FB57EB196558C3B7C765A10D0AE0A411A4E8CB4A28CC34733
sha3_384: 4c626c20a614c45f034c215251714da2ddcb6a16bc307652829c9cb2479fc274914c3fa20031185b83bba5db1713be6f
ep_bytes: b96e000000ff15ca4b40008bd0ff155a
timestamp: 1970-01-01 00:00:00

Version Info:

FileVersion: 5, 2, 3, 1
CompanyName: Hysterocatalepsy
InternalName: Unmortifiedly
Detubation: Pinacoteca
Yogist: Stippling
Chavibetol: Strainlessly
Orthogonally: Ladyling
Timefully: Wyliecoat
Decolorate: Proker
Picturedrome: Chockman
Neoarctic: Infrustrable
Martineta: Shuttlewise
Unseafaring: Jaggery
Maire: Strepsitene
Nickie: Undercreep
Lewdness: Unhealableness
Dehort: Clee
Undullness: Tenontoplasty
Warbled: Plurative
Evovae: Pylic
Volant: Membership
Underconsciousness: Faultsman
Skidpan: Picturedrome
Rhinidae: Toyishly
Clead: Karyomerite
Volcanologist: Assignment
Ferial: Esth
Aldazin: Homocyclic
Cheilodipterus: Complaisantness
Remanipulate: Hotelhood
Limbless: Phlebitis
Analogousness: Misdeed
Polypotome: Anaplasm
Inexorability: Anconeus
Parnel: Accubitus
Batonistic: Poecilonymic
Assertional: Unfellowlike
Azimide: Myriadfold
Kakawahie: Hazing
Waup: Anconeus
Iridectomy: Folial
Milkbush: Stroam
Granulosa: Chanter
Whiggification: Acilius
Nictate: Clunch
Unexuded: Assertrix
Impanation: Manyways
Uncriticizing: Fidia
Uncrochety: Unmixable
Quadragesimal: Catabolite
Dorab: Reaggressive
Enterorrhea: Chauvinist
Atingle: Bodiless
Interrogatedness: Pseudoviscosity
Dungy: Bladderweed
Lecythus: Hydrofluosilicic
Landgraviate: Noneconomic
Scurfiness: Sirki
Vulpicidism: Ponerine
Averter: Centroplasm
Gravimeter: Goniometrically
Mahatma: Gortonian
Kiho: Benthamism
Bluebeardism: Uncompellable
Isopodan: Rander
Untailorlike: Nonmucilaginous
Telautographist: Frogtongue
Undetachable: Unthoughtful
Mattaro: Twineless
Nibsome: Joist
Scottishness: Amah
Patentability: Helvetian
Neologically: Intertonic
Engagedly: Villageress
Bosnisch: Triturate
Pelorization: Unfidgeting
Waterily: Sourdeline
Acacia: Hallucined
Matezite: Poundstone
Preunderstand: Splenization
Syndication: Targeman
Overlipping: Inexplicably
Micraner: Civilization
Endaze: Omoideum
Nigresceous: Jupati
Underfinance: Postfoveal
Litvak: Accelerated
Unitistic: Psychicism
Cloudlike: Shogun
Bullheadedness: Septuplication
Bunton: Anticardium
Entangled: Bigwigged
Heterogeneal: Lactonic
Gamecraft: Venoauricular
Triactinal: Dracocephalum
Unmanacled: Morbific
Undonated: Deathwards
Jennerize: Moneysaving
Dianisidin: Lubritorian
Proker: Kulm
Wormil: Eriosoma
Gnosticize: Stercorist
Slammocking: Lifeful
Brilliandeer: Cleeked
Quarto: Reclose
Macrolepidopterous: Goatly
Unvictorious: Tenontomyotomy
Humulone: Parnel
Precommunion: Phonogramically
Limacinid: Archliar
Bandwork: Tailwards
Alcelaphine: Alodian
Coquetry: Antepast
Malebolgic: Nodated
Paleichthyologist: Plurative
Ferash: Overrigorously
Hyphomycetous: Preindependently
Acarotoxic: Dhoti
Shaps: Stallionize
Unsardonic: Invaried
Poblacht: Phantoscope
Schistoprosopia: Peculiarize
Comer: Scarpment
Disamenity: Triglochin
Pendent: Danglingly
Unpunished: Paraspecific
Knothole: Saleswoman
Weedery: Lopsidedly
Rebroach: Semiostracism
Foggily: Sluer
Danceress: Hexastichic
Aforetimes: Truelike
Malar: Unfurnished
Hyperemphasize: Indefective
Intracosmically: Centroplasm
Overfrequent: Torrentfulness
Startingly: Jacamaralcyon
Hemozoon: Danglingly
Algesia: Homostyled
Volvocaceous: Strifeproof
Unsunburned: Fixature
Hylactic: Quittance
Improgressively: Dogcatcher
Hexadactylic: Auricularis
Benefactory: Lepidote
Stupp: Sciotherical
Cisjurane: Tailage
Subordination: Uncounseled
Induviate: Hysteromorphous
Homothetic: Prehensorial
Amidosulphonal: Producal
Tympanon: Ouenite
Nematoblast: Unwistful
Plenshing: Theopolitician
Assurable: Foreread
Doormaking: Honor
Gombeen: Leuckartia
Intempestively: Turpentinic
Moabitic: Overhasten
Cairngorum: Inarguable
Retrovaccinate: Calcitrate
Tsiltaden: Grillroom
Staphylorrhaphic: Subacademic
Unidentate: Vaporously
Leverwood: Homostyled
Fibrinogenous: Slipperlike
Antisplasher: Unauthorize
Login: Diatessaron
Mentionability: Jeanie
Unionism: Subwink
Thoroughness: Wooer
Cardona: Anticarnivorous
Recivilize: Onicolo
Argumental: Poundstone
Coalify: Coinstantaneity
Flutterment: Aphidozer
Remissibility: Sarcoplasma
Immetrical: Epulary
Reapposition: Hylotheistical
Copperish: Meekling
Annalistic: Metapeptone
Chagan: Snifty
Mycetophagous: Ossiculum
Civilizedness: Xylenol
Erythroplastid: Aplobasalt
Inarguable: Epulary
Drinkableness: Crimpness
Vasectomize: Egoistical
Mennom: Parcher
Superinsaniated: Pendent
Threadbareness: Sanctimonial
Granulator: Nickie
Zigzagwise: Bulbocapnine
Hinderlings: Detentive
Pluralizer: Contentness
Applaudably: Cupidinous
Monazine: Coronilla
Gasserian: Gammexane
Cassia: Babiism
Lymphangiofibroma: Longsomeness
Delignate: Launcher
Nonroutine: Unassigned
Altarlet: Pyrotechnician
Unconcealment: Myxoenchondroma
Yardland: Poundstone
Overfret: Kabardian
Chronotropic: Rhamninase
Retzian: Fratchety
Serflike: Cinephone
Allusively: Paphiopedilum
Nonphagocytic: Euphemy
Diclinism: Spratter
Animalculae: Imperspirable
Fusser: Butterbox
Bacteriohemolysin: Meshy
Grapsidae: Vitelligerous
Unpromising: Misdeed
Tannometer: Substantivity
Lastingness: Triology
Undermiller: Horsewhip
Turgent: Germander
Bicyanide: Aegirinolite
Uncasked: Scalefish
Corvoid: Propodeal
Primulaceous: Goasila
Recumbently: Myxoenchondroma
Aseethe: Veronicellidae
Organoid: Dermis
Noncatechizable: Quadrifid
Butterbox: Nunch
Semiaperture: Diphtheritic
Borofluorin: Casthouse
Remind: Archfriend
Titterel: Erased
Stoollike: Archliar
Puberulent: Lanceolar
Misken: Unheelpieced
Gunstone: Preobservational
Lacroixite: Muddleproof
Unheartsome: Assertional
Pedicurism: Remuneratively
Evenblush: Phantasmatically
Battledore: Tarpot
Bromios: Thoroughness
Photosynthate: Willingness
Matrilineally: Seroreaction
Outservant: Clogdogdo
Atlantad: Cowroid
Humiria: Untall
Favorably: Rapallo
Enslavedness: Aerodromics
Mesendoderm: Gutlike
Turrical: Outpeal
Hoseless: Minorage
Befamine: Subdue
Trustworthiness: Landgraviate
Psychiatria: Albinoism
Smelliness: Promiscuously
Unaptness: Siphonogamy
Unaneled: Talocalcaneal
Fathership: Tora
Aposporous: Gentlehearted
Wooer: Bosnisch
Alecize: Suborder
Sheriffship: Untroublesome
Kabuli: Untarnishable
Oshac: Trucebreaking
Midstreet: Belowstairs
Conceiver: Mensal
Margrave: Munity
Superinduct: Dripstick
Canarium: Metate
Octobrist: Trichiniferous
Nonstatutory: Salivator
Hintingly: Shibar
Lesser: Lightish
Phonophobia: Fathership
Jonvalize: Unidentate
Drumlike: Dighter
Folkright: Sublustrous
Duodenary: Threadbareness
Photophilous: Volable
Protomeristem: Vasifactive
Prairiedom: Crounotherapy
Xeransis: Asymbolical
Abolitionist: Cloop
Duskishness: Houghmagandy
Repercuss: Pneumatologic
Halakistic: Beglerbegship
Zygnemataceae: Poeticism
Reptilious: Agatine
Brakeroot: Preferentialism
Macroscelia: Specificality
Intercome: Averment
Gapa: Kastura
Subadjutor: Readventure
Punti: Brushball
Accouple: Scoptophiliac
Quinzieme: Diatessaron
Omarthritis: Inconversant
Unpenetrated: Homeopolar
Enneastylos: Soporose
Silverbeater: Diaphote
Euosmite: Cyclostomidae
Symptomical: Reminder
Heliogabalus: Heortology
Counteropponent: Tinctorial
Beggarism: Endaze
Pieris: Wagework
Sacaton: Tubularia
Retribute: Rawbones
Rarity: Unmagnetic
Kunbi: Unsung
Blastostylar: Contrantiscion
Semify: Vassalize
Pupilless: Disimpark
Altercation: Unoverdone
Takar: Acetometry
Helenium: Daleman
Antiexporting: Entomophthoraceae
Nitrobacterieae: Planometer
Audiometer: Apothegmatic
Genuinely: Correligionist
Scalefish: Neotremata
Powderiness: Sculler
Numberous: Arterioplania
Unibracteolate: Holothuria
Anglesmith: Reanimalize
Nonelementary: Hieracium
Crepuscular: Tonguey
Overgorge: Cabala
Trilobation: Crystalligerous
Overpersuade: Urethratresia
Pollinator: Monotonical
Stercorist: Achill
Scleratogenous: Cyrtolite
Leant: Mouselet
Cataclysmically: Macarism
Tanjong: Fathership
Thirteenfold: Sluer
Fleuret: Uniquity
Impressionist: Sadalmelik
Cancered: Schematonics
Erased: Thioarsenious
Slavi: Profert
Anamorphoscope: Glandered
Ameliorableness: Metastigmate
Lanai: Direction
Keelhale: Nonorthodox
Centenier: Unsaturatedly
Cinephone: Linchet
Antheroid: Overtrick
Fulgide: Unfurnished
Diplostemony: Pantatrophy
Oophoritis: Mycterism
Electroosmotically: Formicina
Frolicful: Boraciferous
Barbiton: Ungirdled
Paroxysmally: Synthete
Bebothered: Dunair
Militiaman: Telautographist
Madapollam: Coronilla
Contrantiscion: Chromophilous
Semiflint: Nondenumerable
Sunkland: Undramatical
Unjointured: Biron
Policemanism: Outpay
Borean: Samaroid
Silicononane: Usherette
Rahdaree: Yaud
Flacon: Lechriodonta
Logometric: Stylizer
Tosspot: Trilobation
Massebah: Devotedly
Lacinulose: Titaness
Guelphism: Gasifiable
Thielaviopsis: Staphyloplasty
Inninmorite: Antimask
Rotundity: Regalian
Anthrarufin: Multicircuit
Dispeopler: Roughscuff
Adventual: Affreighter
Trasy: Bigwigged
Convulsedly: Fustigator
Invertile: Unoecumenic
Homeless: Marmoraceous
Theotechny: Freakily
Subbasal: Cucullus
Guerdonless: Weekender
Blusterously: Helvetian
Subdial: Dewanee
Tetractinellida: Dereism
Unteacherlike: Heterometabolous
Unvital: Hemiolic
Biotical: Chiffonade
Helldog: Thysanoptera
Sclerodermitis: Overtrace
Antiketogenic: Fishwife
Unhorizontal: Ampullaceous
Fibriform: Undersatisfaction
Uranoscopic: Disorderer
Unfurnished: Nibsome
Urethrostomy: Semiflint
Undergovernor: Tapiroid
Antiquarism: Sufeism
Choreic: Unbreezy
Attargul: Gunstone
Birdy: Zibetone
Convenientness: Hermoglyphic
Prevomer: Solodization
Rinderpest: Amblystegite
Pinbush: Friesic
Noneconomic: Reeveland
Overfacilely: Ichor
Seege: Uninstructible
Anatomicomedical: Inconversant
Embarras: Opisthographical
Scythic: Morphologic
Guttable: Dynamitard
Colorcast: Ileocaecum
Unperspiring: Altarlet
Gumchewer: Consolidative
Eastre: Dismality
Labiovelar: Wrawler
Anticatalyzer: Subbasal
Knowledgement: Smiting
Preferentialism: Peasantess
Flicker: Borasque
Homophone: Freewheeling
Underbough: Hauberget
Undisturbing: Remind
Terrigenous: Interchapter
Puppetlike: Repound
Fetalism: Ischiocapsular
Archexorcist: Foalfoot
Adiaphoristic: Pusillanimousness
Promotress: Chignoned
Indefective: Seege
Grudger: Deathwards
Clabbery: Epicyte
Spartina: Ungouty
Substantivity: Metrophotography
Reconnoitringly: Ungirdled
Unreconnoitered: Hebridean
Whitewood: Spooneyly
Choliambist: Enterorrhea
Echelette: Spartina
Plounce: Gazania
Swindlership: Unrebuffably
Clientship: Overlipping
Vessignon: Ferash
Dicarboxylic: Parfilage
Odylic: Schistoprosopia
Trochozoa: Outlegend
Degreeless: Uninclusiveness
Hers: Pannage
Nonexoneration: Forenoted
Averah: Splendor
Preinsula: Tartronyl
Unwithstanding: Powderiness
Alismataceae: Recollapse
Thacker: Autoproteolysis
Unapprised: Tithable
Somegate: Silence
Beshield: Unman
Rhinolophidae: Prozymite
Feigher: Immetrical
Grouseward: Splother
Inconsumably: Chickenwort
Unmail: Cetoniides
Indehiscence: Batsman
Nuculoid: Metapectus
Insistency: Pyroligneous
Chronometric: Dossel
Notchwing: Ulvales
Accusatrix: Ennoblement
Consentful: Copaivic
Warmongering: Cytopathologically
Hookmaker: Anacamptic
Ultrabasic: Alismataceae
Noncongealing: Untunably
Outstand: Dithiobenzoic
Vitativeness: Ketting
Suiting: Jaspoid
Sluer: Myctodera
Catenary: Synaxis
Cholemia: Outbacker
Hypostatize: Gibbergunyah
Outgrin: Indeficiently
Addititious: Chroococcaceae
Tegean: Unscioned
Michigander: Hypsistenocephalism
Assailment: Buttermouth
Barogram: Confervoid
Uncounseled: Carnassial
Chronogrammic: Unmedicated
Mellowness: Tlingit
Vainness: Calomel
Macrocosmical: Tidingless
Acriflavin: Fonly
Synechthry: Bondless
Unweariness: Rentage
Reluct: Dauntless
Pleximetric: Scoriac
Truelike: Kassak
LegalTrademarks: Tropistic
OriginalFilename: Monazine
PrivateBuild: Mundari
Translation: 0x0409 0x04e4

Win32/Spy.Agent.PRG also known as:

Elasticmalicious (high confidence)
K7AntiVirusSpyware ( 0054b9f91 )
K7GWSpyware ( 0054b9f91 )
EmsisoftTrojan.GenericKD.38677948 (B)
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S + Mal/EncPk-ACO
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=88)
CynetMalicious (score: 100)
McAfeeRDN/Generic PWS.y
RisingBackdoor.Shiz!8.11A (CLOUD)
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Spy.Agent.PRG?

Win32/Spy.Agent.PRG malware is extremely difficult to remove manually. It puts its documents in multiple places throughout the disk, and can restore itself from one of the elements. Additionally, numerous alterations in the windows registry, networking settings and also Group Policies are pretty hard to identify and return to the original. It is far better to use a special app – exactly, an anti-malware tool. GridinSoft Anti-Malware will definitely fit the most ideal for malware elimination goals.

Why GridinSoft Anti-Malware? It is really lightweight and has its detection databases updated just about every hour. Additionally, it does not have such problems and vulnerabilities as Microsoft Defender does. The combination of these facts makes GridinSoft Anti-Malware suitable for clearing away malware of any kind.

Remove the viruses with GridinSoft Anti-Malware

  • Download and install GridinSoft Anti-Malware. After the installation, you will be offered to perform the Standard Scan. Approve this action.
  • Gridinsoft Anti-Malware during the scan process

  • Standard scan checks the logical disk where the system files are stored, together with the files of programs you have already installed. The scan lasts up to 6 minutes.
  • GridinSoft Anti-Malware scan results

  • When the scan is over, you may choose the action for each detected virus. For all files of [SHORT_NAME] the default option is “Delete”. Press “Apply” to finish the malware removal.
  • GridinSoft Anti-Malware - After Cleaning
User Review
0 (0 votes)
Comments Rating 0 (0 reviews)

About the author

Robert Bailey

I'm Robert Bailey, a passionate Security Engineer with a deep fascination for all things related to malware, reverse engineering, and white hat ethical hacking.

As a white hat hacker, I firmly believe in the power of ethical hacking to bolster security measures. By identifying vulnerabilities and providing solutions, I contribute to the proactive defense of digital infrastructures.

Leave a Reply