Malware

Downloader.Win32.Agent.mgmf information

Malware Removal

The Downloader.Win32.Agent.mgmf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mgmf virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

z.whorecord.xyz
w.nanweng.cn
a.tomx.xyz

How to determine Downloader.Win32.Agent.mgmf?


File Info:

crc32: FA89383E
md5: c61c68cf5edeb09199823d90dece4c32
name: adobereaderxipdfE99885E8AFBBE599A852303_3116.exe
sha1: 29c9e0142b78472947d13cf4fa01ace377854e39
sha256: 730888f7e108cd20b5a2e50f1119c107ca573295667a1d69a93ea73d38322a77
sha512: 9cde4963bfaf18e0f24640c0ecd61b592093ae7e38a4e590d8ce4c64f0e42c6a7c9275e5147bccc247504fde7fd6516c5c265275058e923af040784c276c3f1b
ssdeep: 24576:6SCgfZ5B/I74csD+wCLLs0JH9RJfBbCOVhicP9Wb1OXjdY:67s/I7BwmFvFwuiOWROzdY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0325
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0325
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mgmf also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Johnnie.225567
FireEyeGeneric.mg.c61c68cf5edeb091
ALYacGen:Variant.Johnnie.225567
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Variant.Johnnie.225567
K7GWAdware ( 005104d01 )
K7AntiVirusAdware ( 005104d01 )
CyrenW32/S-9ae944ef!Eldorado
SymantecML.Attribute.HighConfidence
GDataGen:Variant.Johnnie.225567
Kasperskynot-a-virus:Downloader.Win32.Agent.mgmf
AlibabaAdWare:Win32/Qjwmonkey.e3ba4280
RisingAdware.Downloader!1.BDCA (CLOUD)
Ad-AwareGen:Variant.Johnnie.225567
SophosGeneric PUA CJ (PUA)
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
EmsisoftGen:Variant.Johnnie.225567 (B)
F-ProtW32/S-9ae944ef!Eldorado
MaxSecureTrojan.Malware.121218.susgen
AviraADWARE/AD.QjwMonkey.hglxv
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Qjwmonkey
Endgamemalicious (high confidence)
ArcabitTrojan.Johnnie.D3711F
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mgmf
MicrosoftPUA:Win32/Qjwmonkey
McAfeeArtemis!C61C68CF5EDE
VBA32BScope.Adware.Qjwmonkey
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R002H0CCV20
YandexPUA.Qjwmonkey!
IkarusPUA.Qjwmonkey
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
Cybereasonmalicious.f5edeb

How to remove Downloader.Win32.Agent.mgmf?

Downloader.Win32.Agent.mgmf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment