Trojan

Trojan.Agent.CGVL information

Malware Removal

The Trojan.Agent.CGVL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CGVL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan.Agent.CGVL?


File Info:

name: 12788E77365A49765E4B.mlw
path: /opt/CAPEv2/storage/binaries/723b9d67f256e3b172d486c49cca01a73c2c8cef0dff071a7b3d47c084d403ac
crc32: 973AF3E6
md5: 12788e77365a49765e4ba01d2baf241d
sha1: 08a9924b536a1db71688fab04bf64da80d984090
sha256: 723b9d67f256e3b172d486c49cca01a73c2c8cef0dff071a7b3d47c084d403ac
sha512: 5d08534189310590df8dfb720304e1b8f979a971e414d44f63e82773175b6f5351c5f7ae41452fb66ae98a7b938643a00e42421eb893c22c7fc9eeeb4ed831a7
ssdeep: 6144:Jvrb22uGLbWhTjYes+PfGGPmRFJs0ug1MOcKfE:JDb22DShTEx+PfGG0s0udOu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19214CF21BAA4C036D8E3157056ACE6725A3D7A720B388ACB365457EE5DF13C1EE38317
sha3_384: 6836ac5c12b2ac29e5a3ff5e2dc45cef5fe9dbd55f7c8f3949c82b41a303c02a3533ef50750c293ad60cc309b9659ef3
ep_bytes: 60be00a042008dbe0070fdffc78708d7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Agent.CGVL also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (moderate confidence)
DrWebTrojan.Siggen3.61405
MicroWorld-eScanTrojan.Agent.CGVL
FireEyeGeneric.mg.12788e77365a4976
CAT-QuickHealTrojan.GenericIH.S24070444
McAfeePWS-CangKu
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.Agent.CGVL
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaAI:Packer.A91EC2291F
CyrenW32/Legendmir.XJFG-4309
SymantecW32.HLLP.Philis
ESET-NOD32Win32/PSW.Legendmir.OA
TrendMicro-HouseCallPE_LEGMIR.B
ClamAVWin.Trojan.Lmir-24
NANO-AntivirusTrojan.Win32.Lmir.dxaowj
AvastWin32:Delf-AFC [Trj]
TencentVirus.Win32.Syphilis.a
Ad-AwareTrojan.Agent.CGVL
TACHYONVirus/W32.Philis
ComodoTrojWare.Win32.PSW.Legendmir.OA@2lge
F-SecureMalware.W32/PSW.Lmir.oa
BaiduWin32.Trojan-PSW.OLGames.be
ZillyaTrojan.Lmir.Win32.762
TrendMicroPE_LEGMIR.B
McAfee-GW-EditionBehavesLike.Win32.PWSLegMir.cc
SophosML/PE-A + W32/LegMir-BM
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.LMir.ec
AviraW32/PSW.Lmir.oa
Antiy-AVLTrojan/Win32.Philis.a
ArcabitTrojan.Agent.CGVL
ViRobotTrojan.Win32.PSWLmir.84992.B
ZoneAlarmTrojan-GameThief.Win32.Lmir.oa
MicrosoftVirus:Win32/Viking.MP
CynetMalicious (score: 100)
AhnLab-V3Win32/Lemir.212992
Acronissuspicious
VBA32Trojan.Sabsik.FL
ALYacTrojan.Agent.CGVL
MAXmalware (ai score=84)
MalwarebytesMalware.AI.2382208213
APEXMalicious
RisingTrojan.PSW.Qiji.s (RDMK:cmRtazrfSMojAj7KfVdk1ue1EpoQ)
YandexTrojan.GenAsa!l4kdDOnxqiQ
IkarusTrojan-PWS.Win32.Lmir.mw
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Lmir.7128!tr
AVGWin32:Delf-AFC [Trj]
Cybereasonmalicious.7365a4
PandaW32/Legmir.J

How to remove Trojan.Agent.CGVL?

Trojan.Agent.CGVL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment