Malware

Downloader.Win32.Agent.mgmg removal guide

Malware Removal

The Downloader.Win32.Agent.mgmg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mgmg virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.mgmg?


File Info:

crc32: 266D1E71
md5: e35d3dbe92fa669b37d6760009046c46
name: E799BEE8AF8DE696A9E794B5E88491E789881554_431700.exe
sha1: 960a76887541c794360b4791a99d8b956f625729
sha256: 6c053bfb70806c13050f91aa2d11a6451b638e1ac15edc6e4bf9ae0e6b378bfd
sha512: 3b1cfb5694f754665862241934fedfb78d8c46a267d67eefec4b3b333a09b62cc1167b2d6d15bd55a0b72ae50a0c6aed2341a2f2da7bd608c737afa116784bdc
ssdeep: 24576:2SCgfZ5B/I74csD+wCLLs0JH9RJfBbCOVhicP9Wb1OXjdY:27s/I7BwmFvFwuiOWROzdY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0325
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0325
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mgmg also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Johnnie.225567
FireEyeGeneric.mg.e35d3dbe92fa669b
ALYacGen:Variant.Johnnie.225567
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005104d01 )
BitDefenderGen:Variant.Johnnie.225567
K7GWAdware ( 005104d01 )
Cybereasonmalicious.e92fa6
Invinceaheuristic
F-ProtW32/S-9ae944ef!Eldorado
SymantecML.Attribute.HighConfidence
GDataGen:Variant.Johnnie.225567
Kasperskynot-a-virus:Downloader.Win32.Agent.mgmg
AlibabaAdWare:Win32/Qjwmonkey.e3ba4280
RisingAdware.Downloader!1.BDCA (CLOUD)
Ad-AwareGen:Variant.Johnnie.225567
SophosGeneric PUA JG (PUA)
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
McAfee-GW-EditionArtemis!PUP
EmsisoftGen:Variant.Johnnie.225567 (B)
IkarusPUA.Qjwmonkey
CyrenW32/S-9ae944ef!Eldorado
eGambitUnsafe.AI_Score_100%
AviraADWARE/AD.QjwMonkey.hglxv
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Qjwmonkey
Endgamemalicious (high confidence)
ArcabitTrojan.Johnnie.D3711F
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mgmg
MicrosoftPUA:Win32/Qjwmonkey
McAfeeArtemis!E35D3DBE92FA
VBA32BScope.Adware.Qjwmonkey
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R002H0CCV20
YandexPUA.Qjwmonkey!
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qjwmonkey.KD!tr
WebrootW32.Adware.Gen
AVGWin32:MdeClass

How to remove Downloader.Win32.Agent.mgmg?

Downloader.Win32.Agent.mgmg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment