Malware

Application.Downloader.AGO (file analysis)

Malware Removal

The Application.Downloader.AGO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Downloader.AGO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

Related domains:

api.eazymount.com

How to determine Application.Downloader.AGO?


File Info:

crc32: B37947C2
md5: 4201250f896431976852917bc1e810b7
name: 4201250F896431976852917BC1E810B7.mlw
sha1: 3c199d5cc401e0fc66c71c792cf8cc44e5e6abcb
sha256: dfd03df4fc9b9599a935493d082d5925532bb4b4cda694e5cc0ce76a0f3b74f9
sha512: 814eb8fecd8991c400e311153a39679d648212f08bcb7db88bc84dec8bd969d6d61cc75bcafe04ccfc548a7dea43a6d82da518e0f8cfcf9b4a0ed56826c8957b
ssdeep: 3072:Iwr9Vdur8AgBt18FP8zaAOdnFpMzC/8/ArrdRjfOHrcQH1GDeHfDyZ5fsIYQbU3:dr9Wr8AIt10P8z+Fp0/ArrdRaHRDDwb
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.695
InternalName: installer.exe
FileVersion: 1.0.0.695
ProductVersion: 1.0.0.695
FileDescription:
OriginalFilename: installer.exe

Application.Downloader.AGO also known as:

K7AntiVirusAdware ( 004dc60a1 )
LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.30841
CynetMalicious (score: 99)
ALYacApplication.Downloader.AGO
CylanceUnsafe
ZillyaTool.Downloader.Win32.3850
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:MSIL/Amonetize.6791026d
K7GWAdware ( 004dc60a1 )
Cybereasonmalicious.f89643
CyrenW32/S-524e6fcc!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Amonetize.AF potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Packed.Susppack-9881847-0
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Agent.gen
BitDefenderApplication.Downloader.AGO
NANO-AntivirusRiskware.Win32.Amonetize.ebhypd
MicroWorld-eScanApplication.Downloader.AGO
TencentWin32.Adware.Generic.Oyof
Ad-AwareApplication.Downloader.AGO
SophosGeneric PUA DM (PUA)
ComodoApplication.MSIL.Amonetize.AF@67z1tc
BitDefenderThetaGen:NN.ZemsilF.34170.km0@aC!dUnm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.4201250f89643197
EmsisoftApplication.Downloader.AGO (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.bzkw
WebrootW32.Adware.Gen
AviraADWARE/Amonetize.Gen7
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.17C2D88
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywarePUP.Amonetize/Variant
GDataApplication.Downloader.AGO
AhnLab-V3PUP/Win32.Amonetize.C1350116
McAfeeArtemis!4201250F8964
MAXmalware (ai score=79)
MalwarebytesPUP.Optional.Amonetize
PandaTrj/GdSda.A
YandexPUA.Agent!lLbHQAuumfc
Ikarusnot-a-virus:AdWare.Amonetize
FortinetAdware/Generic
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Application.Downloader.AGO?

Application.Downloader.AGO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment