Malware

VirTool:Win32/Obfuscator.AGS (file analysis)

Malware Removal

The VirTool:Win32/Obfuscator.AGS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.AGS virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine VirTool:Win32/Obfuscator.AGS?


File Info:

name: E8127B3674B9AB1F5DEC.mlw
path: /opt/CAPEv2/storage/binaries/82967c485fba10913eb8681f727d3789ac9d5f6c9a8e86b1b94c44161fdf6872
crc32: 16E4DE77
md5: e8127b3674b9ab1f5dec02bd1b9d9fd2
sha1: 1562cdfa43f8d42afb6f0fde1245725db0904a25
sha256: 82967c485fba10913eb8681f727d3789ac9d5f6c9a8e86b1b94c44161fdf6872
sha512: c44aa4df1d21615313525aa0337fa95ba5d665d63174e5b3c9cfbb7200a5dec9e56e12b516d198997c8917aac4a4dead18045d78983b2676eb008b2dbbd02f45
ssdeep: 768:qf1Ai9XHEcOcCc4tumk1ioPveiNNjn3UPDoiK:w1AMXEZcCXtePvrJn3U9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18DD2BF57F16D367AF07829B095061AC80E8DD1322C799685EF6EF3362A2044F977CF4A
sha3_384: a30a75e839f8a73f7d4d78a770345f57fb6f9b521d73c26277875edc1d9453237796721a26ff445007d213fcf5dd728b
ep_bytes: 558bec83ec2c5333c05657c645d445c6
timestamp: 2087-11-04 07:51:30

Version Info:

0: [No Data]

VirTool:Win32/Obfuscator.AGS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lpBA
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.71978
ClamAVWin.Trojan.Agent-1344906
FireEyeGeneric.mg.e8127b3674b9ab1f
ALYacGen:Variant.Cerbu.71978
MalwarebytesMalware.AI.3418690526
SangforRootkit.Win32.Ressdt.Vnit
K7AntiVirusTrojan ( 0035c1b31 )
AlibabaRootkit:Win32/Ressdt.301f12d0
K7GWTrojan ( 0035c1b31 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Rootkit.Agent.c
VirITTrojan.Win32.NtRootKit.WNS
CyrenW32/Rootkit.J.gen!Eldorado
SymantecHacktool.Rootkit
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Rootkit.Kryptik.BR
APEXMalicious
CynetMalicious (score: 100)
KasperskyRootkit.Win32.Ressdt.dhs
BitDefenderGen:Variant.Cerbu.71978
NANO-AntivirusTrojan.Win32.Kryptik.vpldf
SUPERAntiSpywareTrojan.Agent/Gen-Mondar
AvastWin32:Agent-ADMW [Rtk]
TencentTrojan.Win32.Rootkit.cvp
EmsisoftGen:Variant.Cerbu.71978 (B)
F-SecureTrojan.TR/Rootkit.Gen
DrWebTrojan.NtRootKit.19442
VIPREGen:Variant.Cerbu.71978
TrendMicroRTKT_ZACESS.SMAR
McAfee-GW-EditionZeroAccess.eg
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusVirTool.WinNT.Mondae
GDataGen:Variant.Cerbu.71978
JiangminTrojan/Generic.aeuyt
AviraTR/Rootkit.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan[Rootkit]/Win32.Ressdt.dhs
XcitiumTrojWare.Win32.Rootkit.ZAccess.LF@4m28pc
ArcabitTrojan.Cerbu.D1192A
ViRobotTrojan.Win32.Agent.29568
ZoneAlarmRootkit.Win32.Ressdt.dhs
MicrosoftVirTool:Win32/Obfuscator.AGS
GoogleDetected
AhnLab-V3Trojan/Win32.Banbra.R34032
McAfeeZeroAccess.eg
TACHYONTrojan/W32.Rootkit.29568.G
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallRTKT_ZACESS.SMAR
RisingRootKit.Win32.Undef.cvu (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureRootkit.Ressdt.dhs
FortinetW32/Ressdt.NAT!tr.rkit
AVGWin32:Agent-ADMW [Rtk]
Cybereasonmalicious.674b9a
DeepInstinctMALICIOUS

How to remove VirTool:Win32/Obfuscator.AGS?

VirTool:Win32/Obfuscator.AGS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment