Malware

Downloader.Win32.Agent.mgbc removal guide

Malware Removal

The Downloader.Win32.Agent.mgbc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mgbc virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.mgbc?


File Info:

crc32: 4D593859
md5: ceb54f199e7ec56c3931044779e50cf8
name: E4B88BE8BDBDE599A8.exe
sha1: 6ea0abfe6d755a55ad54919e6224bb08fddd343c
sha256: c1ea3c6d8f466ca7ea32adbd92885b35af26de7608d61430f0b04fd2a2fa18da
sha512: 23cb6ce463b76ad859c87ffeae3c5b282b3a03292087b029a0de9721a375b1cb3584962335dd739bdc981e4cbe0cd8e8e459177e89c00297dc524d25c02807b9
ssdeep: 24576:g7WGksNMSumx86mbyZDXj7mUOHX2Jy1xBz9SwTtZsSomHG0txdk:Xmx86Dz03q4Z3DHG0Tdk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0318
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0318
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mgbc also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33563167
FireEyeGeneric.mg.ceb54f199e7ec56c
McAfeeArtemis!CEB54F199E7E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 005105151 )
BitDefenderTrojan.GenericKD.33563167
K7GWAdware ( 005105151 )
Invinceaheuristic
F-ProtW32/S-9ae944ef!Eldorado
Paloaltogeneric.ml
GDataTrojan.GenericKD.33563167
Kasperskynot-a-virus:Downloader.Win32.Agent.mgbc
AlibabaDownloader:Win32/Qjwmonkey.0d7a4189
RisingAdware.Downloader!1.BDCA (CLOUD)
Ad-AwareTrojan.GenericKD.33563167
EmsisoftTrojan.GenericKD.33563167 (B)
ComodoApplicUnwnt@#14l7upywahb36
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
ZillyaAdware.Qjwmonkey.Win32.630
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA GO (PUA)
IkarusPUA.Qjwmonkey
CyrenW32/S-9ae944ef!Eldorado
JiangminDownloader.Agent.myu
WebrootW32.Adware.Gen
AviraADWARE/AD.QjwMonkey.dneew
MAXmalware (ai score=96)
Antiy-AVLRiskWare[Downloader]/Win32.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D200221F
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mgbc
MicrosoftPUA:Win32/Qjwmonkey
AhnLab-V3PUP/Win32.Installer.C4021483
VBA32BScope.Adware.Qjwmonkey
MalwarebytesAdware.Qjwmonkey
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R049H0CCO20
TencentMalware.Win32.Gencirc.10b96896
YandexPUA.Qjwmonkey!
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGWin32:Adware-gen [Adw]
AvastWin32:Adware-gen [Adw]
MaxSecureTrojan.Malware.121218.susgen

How to remove Downloader.Win32.Agent.mgbc?

Downloader.Win32.Agent.mgbc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment