Malware

Application.Downloader.AEG removal instruction

Malware Removal

The Application.Downloader.AEG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Downloader.AEG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Application.Downloader.AEG?


File Info:

name: 906F9B3EC0E8E09DBEDB.mlw
path: /opt/CAPEv2/storage/binaries/75c2eb163232dd6758ea89a6b180d733449155b3315be6ef7219ab001e175ac6
crc32: 23002691
md5: 906f9b3ec0e8e09dbedb6099239d8d96
sha1: f7ae779c72a81965a1e966bd8845616f501377c5
sha256: 75c2eb163232dd6758ea89a6b180d733449155b3315be6ef7219ab001e175ac6
sha512: 2b8a43fe1089fdd3a25657aaca2694bc8579ed162b1971db50d7e838986c28d588100d6bf4ef9e9f0f1fd607f0e562af711d83838591780dde9632f8df00bfb4
ssdeep: 24576:guYIC81vsIwYDf/MPdihDSBuz6p9STviYy8:IJsuYDf/9DSoliA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13615234FE78380FAEDE4977694A242710827B627479CE6C779D4CF66E6203C81CB65C8
sha3_384: 41b3561d088e692b5afd7ba33669c6c977596127e730f9c22ee7fbeffa3d5c2fe6fb435a9c07f894141696ee9dc4f3a6
ep_bytes: e8459d0000e947960000535556578b7c
timestamp: 2015-02-16 23:55:27

Version Info:

OriginalFilename: setup.exe
FileDescription: Red Light Media
InternalName: setup.exe
CompanyName: Red Light Media
FileVersion: 42.3.6.7142
LegalCopyright: Copyright (C) 2015
ProductName: Red Light Media
ProductVersion: 42.3.6.7142
Translation: 0x0409 0x04b0

Application.Downloader.AEG also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ocna.mC7f
AVGFileRepMalware [Misc]
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Downloader.AEG
FireEyeGeneric.mg.906f9b3ec0e8e09d
CAT-QuickHealPUA.Redlightme.Gen
SkyhighGenericRXFI-RW!906F9B3EC0E8
ALYacApplication.Downloader.AEG
Cylanceunsafe
VIPREApplication.Downloader.AEG
SangforVirus.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36802.3q3@aCUkDKai
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/DownloadAdmin.Q potentially unwanted
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Downloadadmin-318
Kasperskynot-a-virus:Downloader.Win32.DownloAdmin.azwh
BitDefenderApplication.Downloader.AEG
NANO-AntivirusTrojan.Win32.Vittalia.eakead
SUPERAntiSpywarePUP.DownloadAdmin/Variant
AvastFileRepMalware [Misc]
TencentMalware.Win32.Gencirc.10beb71e
EmsisoftApplication.Downloader.AEG (B)
F-SecurePotentialRisk.PUA/Downloadadmin.KG
DrWebTrojan.Vittalia.8197
ZillyaDownloader.DownloAdminCRTD.Win32.6437
TrendMicroPUA_DOWNADMIN.SM
Trapminemalicious.high.ml.score
SophosDownload Admin (PUA)
IkarusPUA.Optional.Install
GDataApplication.Downloader.AEG
JiangminDownloader.DownloAdmin.e
VaristW32/S-460eee50!Eldorado
AviraPUA/Downloadadmin.KG
Antiy-AVLGrayWare[AdWare]/Win32.DownloadAdmin.q
Kingsoftmalware.kb.a.999
XcitiumApplication.Win32.DownloadAdmin.Q@6azwtv
ArcabitApplication.Downloader.AEG
ViRobotAdware.Downloadadmin.910384.G
ZoneAlarmnot-a-virus:Downloader.Win32.DownloAdmin.azwh
MicrosoftPUADlManager:Win32/DownloadAdmin
GoogleDetected
AhnLab-V3PUP/Win32.DownloadAdmin.R174964
Acronissuspicious
McAfeeGenericRXFI-RW!906F9B3EC0E8
MAXmalware (ai score=71)
VBA32BScope.Downloader.DownloAdmin
MalwarebytesPUP.Optional.DownLoadAdmin.DDS
PandaPUP/Multitoolbar
TrendMicro-HouseCallPUA_DOWNADMIN.SM
RisingAdware.DownloadAdmin!1.A4A7 (CLASSIC)
YandexRiskware.Agent!Xbp4NFk2k5s
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.9185910.susgen
FortinetRiskware/DownloadAdmin
Cybereasonmalicious.ec0e8e
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/DownloAdmin.azwh

How to remove Application.Downloader.AEG?

Application.Downloader.AEG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment