Malware

Should I remove “Application.StartPage.AGV”?

Malware Removal

The Application.StartPage.AGV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.StartPage.AGV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

Related domains:

www.kk3456.com
www.pp1234.net

How to determine Application.StartPage.AGV?


File Info:

crc32: 4762BDB1
md5: ab2daf38d9222fab511ba395d8f38a40
name: AB2DAF38D9222FAB511BA395D8F38A40.mlw
sha1: 7aaa2ef4521c29c5a999bde785f085f7e904e760
sha256: 1e04c1fa0ad5129479791d3c9fe07f4adca56e86e9478a379ed192973068e6c5
sha512: 597bb381c5c1d6d87b33a8f08a5fb741a822373abe378c99c9f29b2abcc2882b66aed4dfbcf5551290fc69c07faae968191d178dfcfb208784d3d83b9eecaa89
ssdeep: 6144:ws61UAWj2CBHjjnMG6Nd/qfwn3M94cBnDNaelO7CsuWGzUczS116:jAWj2CxHMGi1Awc94cBDjJWWUD6
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: (C)
FileVersion: 2010.09.17
CompanyName: www.haote.com
LegalTrademarks: 2011-05-27_2:57:22
Comments:
FileDescription: Producer [zw]
Translation: 0x0804 0x04e4

Application.StartPage.AGV also known as:

K7AntiVirusTrojan-Downloader ( 00005c601 )
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.8928
CynetMalicious (score: 99)
ALYacApplication.StartPage.AGV
CylanceUnsafe
ZillyaTrojan.Agent.Win32.984118
AlibabaTrojanDownloader:Win32/Generic.3b9ed17e
K7GWTrojan-Downloader ( 00005c601 )
Cybereasonmalicious.4521c2
BaiduNSIS.Trojan-Downloader.Agent.cs
SymantecML.Attribute.HighConfidence
ESET-NOD32NSIS/TrojanDownloader.Agent.NKQ
APEXMalicious
AvastNSIS:Downloader-XL [Trj]
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderApplication.StartPage.AGV
NANO-AntivirusTrojan.Nsis.Dwn.cwyaqn
MicroWorld-eScanApplication.StartPage.AGV
TencentNsis.Trojan-downloader.Agent.Lmkr
SophosMal/Generic-S
ComodoMalware@#3vr3nqj3ir2lw
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeApplication.StartPage.AGV
EmsisoftAdware.Downloader (A)
AviraHEUR/AGEN.1129091
eGambitUnsafe.AI_Score_72%
Antiy-AVLTrojan/Generic.ASMalwNS.6
KingsoftWin32.Troj.newyx.sc.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitApplication.StartPage.AGV
GDataNSIS.Application.KuaiSearch.B
McAfeeAdware-Agent
MAXmalware (ai score=99)
PandaTrj/CI.A
FortinetAdware/StartPage
AVGNSIS:Downloader-XL [Trj]
Paloaltogeneric.ml

How to remove Application.StartPage.AGV?

Application.StartPage.AGV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment