Malware

Mal/Agent-AUG removal instruction

Malware Removal

The Mal/Agent-AUG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Agent-AUG virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Agent-AUG?


File Info:

crc32: D6BFD399
md5: 42913ce0112c87deec852f9ae9a53f9c
name: tmpcagssn32
sha1: ec22e0142319afdd66daea923e3fce794ab0abff
sha256: ebbe6a7d2a36a8b876ec778742fedcfb0b612769e052f41bb729057421197c9f
sha512: adad84ba248915aeaa0c17b324df985d7b8ee90d447425594e311768bb3db53dfb0b716fa2934b350614c8a41df88c97df65c38abeefef8803d5b8b09a0a68ed
ssdeep: 393216:XcpiiBCS4+xJVLU8IXh7bSqOEScDD3NIQcyOhC8Dzi:INB/xrIbccDT6vyOh36
type: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive

Version Info:

LegalCopyright: (C)
ProductName:
FileVersion:
FileDescription: Producer shd
Translation: 0x0804 0x04e4

Mal/Agent-AUG also known as:

MicroWorld-eScanTrojan.GenericKD.31747835
CAT-QuickHealW32.Ramnit.A
McAfeeArtemis!42913CE0112C
CylanceUnsafe
K7AntiVirusTrojan ( 0050b64b1 )
BitDefenderTrojan.GenericKD.31747835
K7GWTrojan ( 0050b64b1 )
Cybereasonmalicious.0112c8
Invinceaheuristic
BaiduMulti.Threats.InArchive
F-ProtW32/Ramnit.B!Generic
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Ramnit-1847
GDataTrojan.GenericKD.31747835
KasperskyVirus.Win32.Nimnul.a
AlibabaVirus:Win32/Nimnul.4838abef
NANO-AntivirusVirus.Win32.Ramnit.eslalb
AvastWin32:RmnDrp
TencentMalware.Win32.Gencirc.10b3ee0c
Ad-AwareTrojan.GenericKD.31747835
EmsisoftAdware.Dropper (A)
F-SecureMalware.W32/Ramnit.CD
DrWebAdware.Searcher.1222
ZillyaTrojan.Zbot.Win32.188716
TrendMicroPE_RAMNIT.H
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.42913ce0112c87de
SophosMal/Agent-AUG
IkarusVirus.Ramnit
CyrenW32/Ramnit.B!Generic
WebrootW32.Malware.Heur
AviraW32/Ramnit.CD
eGambitUnsafe.AI_Score_91%
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.StartPage.gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E46EFB
ZoneAlarmVirus.Win32.Nimnul.a
MicrosoftVirus:Win32/Ramnit.A
Acronissuspicious
ALYacTrojan.GenericKD.31747835
VBA32Adware.Searcher
MalwarebytesTrojan.ChinAd
ZonerTrojan.Win32.Ramnit.23698
ESET-NOD32a variant of NSIS/TrojanDropper.Agent.BT
TrendMicro-HouseCallPE_RAMNIT.H
RisingVirus.Ramnit!1.9AA5 (CLASSIC:bWQ1OthrKJn0I5MRMbaW/2Wap+0)
SentinelOneDFI – Suspicious PE
MaxSecureVirus.Nimnul.A
BitDefenderThetaAI:FileInfector.EAEEA7850C
AVGWin32:RmnDrp
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360QVM42.0.Malware.Gen

How to remove Mal/Agent-AUG?

Mal/Agent-AUG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment