Malware

What is “AdWare.Win32.Agent.xxzagf”?

Malware Removal

The AdWare.Win32.Agent.xxzagf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Agent.xxzagf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Detects VirtualBox using WNetGetProviderName trick
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine AdWare.Win32.Agent.xxzagf?


File Info:

name: 168EDF7A0C82AC8CB729.mlw
path: /opt/CAPEv2/storage/binaries/cc0cd2e99f0e2c5600f8e4fbcb29a0d5417f48737f3da48bf5c5f39df513deb2
crc32: 0A2C9684
md5: 168edf7a0c82ac8cb729626e372db1c6
sha1: 0bd0205958eee0adf265bb1e18ea0e1800110050
sha256: cc0cd2e99f0e2c5600f8e4fbcb29a0d5417f48737f3da48bf5c5f39df513deb2
sha512: c424f6a267bf60f85bf611425b4f4b026e80f1307e0247b2fe02c839cbacbead86cc770e81821aede73965498256c6f4b555154ed9a7f64a25243fa4ad2a3ad5
ssdeep: 196608:Vqoe8XpbfeR0z5v+qHxXtws3Cp5nGAdmbxR0HETIRyrNvpx9wlKB:8oe8552APPu5nGAdmbxR0kTI0rNvpx93
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158963367969B0235F7648931C8A180419D92FC367AF2E06F1C7AFE0E9EB4241CB36775
sha3_384: 59d7a8b8f92e788054b2940ffc889fc73e6134c73c65b3fd87185af543eefb3c79e0a296fb3f942bd0f73a7a10728e95
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2015-07-16 13:24:20

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Auslogics Labs Pty Ltd
FileDescription: TweakBit PCSpeedUp Installation File
FileVersion: 1.7.1.3
LegalCopyright: Copyright © 2008-2016 Auslogics Labs Pty Ltd
ProductName: TweakBit PCSpeedUp
ProductVersion: 1.7.1.3
Translation: 0x0000 0x04b0

AdWare.Win32.Agent.xxzagf also known as:

LionicAdware.Win32.Agent.2!c
FireEyeGeneric.mg.168edf7a0c82ac8c
McAfeeArtemis!168EDF7A0C82
CylanceUnsafe
SangforAdware.Win32.Agent.xxzagf
K7AntiVirusRiskware ( dec000a21 )
K7GWRiskware ( dec000a21 )
ESET-NOD32a variant of Win32/Auslogics.AB potentially unwanted
Kasperskynot-a-virus:AdWare.Win32.Agent.xxzagf
SophosGeneric Reputation PUA (PUA)
DrWebProgram.Unwanted.1336
McAfee-GW-EditionArtemis!PUP
GDataWin32.Application.Auslogics.C
Antiy-AVLTrojan/Generic.ASCommon.184
MicrosoftPUA:Win32/Auslogics
VBA32Adware.Agent
MalwarebytesPUP.Optional.TweakBit
FortinetW32/Auslogics.A

How to remove AdWare.Win32.Agent.xxzagf?

AdWare.Win32.Agent.xxzagf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment