Malware

Should I remove “Downloader.Win32.Agent.mgkv”?

Malware Removal

The Downloader.Win32.Agent.mgkv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mgkv virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.mgkv?


File Info:

crc32: E8072D2C
md5: 18538bde971f9ee359357df17d0adfb2
name: ax88772cusbE7BD91E58DA1311_17951.exe
sha1: 17e7ddcc09918b9d66cbb0a1b09aee263c78effb
sha256: 1f9476e3c08cd4dacab60cc9bf4d3d1d383b69c7b3245bac9a0fa4afcba81008
sha512: d4f7f0d732f9b1af72d7a4ad95c16e9b2f8cd2b95922635c8dffd76777b48ea96879b87de0cce2f30df79f5d21c29a51fe5b691d4e58073dd5685d4c32b6d45c
ssdeep: 24576:TSCgfZ5B/I74csD+wCLLs0JH9RJfBbCOVhicP9Wb1OXjdYX:T7s/I7BwmFvFwuiOWROzdYX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0325
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0325
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mgkv also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Johnnie.225567
FireEyeGeneric.mg.18538bde971f9ee3
McAfeeArtemis!18538BDE971F
SangforMalware
K7AntiVirusAdware ( 005104d01 )
BitDefenderGen:Variant.Johnnie.225567
K7GWAdware ( 005104d01 )
Cybereasonmalicious.e971f9
SymantecML.Attribute.HighConfidence
GDataGen:Variant.Johnnie.225567
Kasperskynot-a-virus:Downloader.Win32.Agent.mgkv
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Johnnie.225567 (B)
F-SecureAdware.ADWARE/Qjwmonkey.ihefe
DrWebAdware.Qjwmonkey.168
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA BH (PUA)
IkarusPUA.Qjwmonkey
CyrenW32/Trojan.UEVB-8727
AviraADWARE/Qjwmonkey.ihefe
MAXmalware (ai score=83)
ArcabitTrojan.Johnnie.D3711F
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mgkv
MicrosoftPUA:Win32/Qjwmonkey
VBA32BScope.Adware.Qjwmonkey
ALYacGen:Variant.Johnnie.225567
Ad-AwareGen:Variant.Johnnie.225567
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
RisingAdware.Downloader!1.BDCA (CLOUD)
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGFileRepMetagen [Adw]
MaxSecureTrojan.Malware.121218.susgen

How to remove Downloader.Win32.Agent.mgkv?

Downloader.Win32.Agent.mgkv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment