Malware

Downloader.Win32.Agent.mgib malicious file

Malware Removal

The Downloader.Win32.Agent.mgib is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mgib virus can do?

  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (9 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Exhibits possible ransomware file modification behavior

Related domains:

2398.35go.net
infoc0.duba.net
dubacdn.cmcmcdn.com
config.i.duba.net
cd001.www.duba.net
did.ijinshan.com
ct.duba.net

How to determine Downloader.Win32.Agent.mgib?


File Info:

crc32: 42B20D4A
md5: da1e87ee9169681816adb3f8cd0e47e8
name: _______________.exe
sha1: ec59bca3626db66dc9687ffd1c772fe64191917f
sha256: 0594c623303ec44ca0447853f1e3ac107549298603b737bcb947b0ffbf784b7b
sha512: be53e183f00512d8ae7b6b0fbfc35b75fc97e0db938bdc9fd0d104d9831c92c0abc527916f5832754b4df3e6417093c4e8ea9e018dfb8328dfcf0f91dba15648
ssdeep: 24576:pAVB/J7aY4Jb9mwjCDhpPaYcgd/NBjvsuGtQjNYm+8m5C7ZFwDjNT0eQiUMB/MQ:pAnJuTb9GDhpPaY9TRYm+TAXEdyiUMBb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Downloader.Win32.Agent.mgib also known as:

AegisLabRiskware.Win32.Agent.1!c
Kasperskynot-a-virus:Downloader.Win32.Agent.mgib
AlibabaDownloader:Win32/KingSoft.bbfb8111
SophosGeneric PUA OM (PUA)
McAfee-GW-EditionArtemis
JiangminDownloader.Agent.myo
WebrootW32.Adware.Gen
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mgib
AhnLab-V3PUP/Win32.Installer.C4008344
McAfeeArtemis!DA1E87EE9169
VBA32BScope.Adware.Presenoker
ESET-NOD32a variant of Win32/KingSoft.L potentially unwanted
MaxSecureTrojan.Malware.73670114.susgen
FortinetRiskware/Agent

How to remove Downloader.Win32.Agent.mgib?

Downloader.Win32.Agent.mgib removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment