Malware

About “Win32/Agent.AAUV” infection

Malware Removal

The Win32/Agent.AAUV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.AAUV virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Created a service that was not started

How to determine Win32/Agent.AAUV?


File Info:

name: 4CD3187E1E5BA0C1FD52.mlw
path: /opt/CAPEv2/storage/binaries/b55baceb7dc8e609537a29978d52f9c77e737f648cbcdd79be2cf6115c567096
crc32: E0BEC13D
md5: 4cd3187e1e5ba0c1fd52aa15274f0175
sha1: 44c3145a852dae46219c78a97e4f0e16b30b6e8b
sha256: b55baceb7dc8e609537a29978d52f9c77e737f648cbcdd79be2cf6115c567096
sha512: e5c90d8dac82901fb05ad69f16b0acf14f5b2cf475a6f28ae3a17c06703d35d70a7021177371a63612b214b3545afb30b280b05d5d370fa845d80cd5785d5d10
ssdeep: 12288:oxaCvSzRJ1WVOFQnz1nJbCKURRaR+GX6mf4g2d8pT0EmFfZuO75Ptla:8jf15t2mf0EAft
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T158B4BF53AF80D0B3D186117461A6CB761D7A773A0329DBC3E3C04E755E747E2AA3938A
sha3_384: 42843ba08cc25446ed6029aec443d16b4def407358be109012a31d5438815cb12792ddad5b32c8b1467799b822a7b2be
ep_bytes: 8bff558bec837d0c017505e8c9ed0000
timestamp: 2023-05-11 02:45:38

Version Info:

CompanyName: 武汉酩悦贸易有限公司
FileDescription: FileZhuoYiHost 动态链接库
FileVersion: 1, 0, 1, 23
LegalCopyright: Copyright (C) 2023 武汉酩悦贸易有限公司
ProductName: FileZhuoYiHost 动态链接库
ProductVersion: 1, 0, 1, 23
Translation: 0x0804 0x04b0

Win32/Agent.AAUV also known as:

BkavW32.Common.ABF61A10
Elasticmalicious (high confidence)
FireEyeGeneric.mg.4cd3187e1e5ba0c1
SkyhighArtemis
McAfeeArtemis!4CD3187E1E5B
Cylanceunsafe
K7AntiVirusTrojan ( 00569e4d1 )
K7GWTrojan ( 00569e4d1 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.AAUV
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
VaristW32/Burden.G.gen!Eldorado
GoogleDetected
IkarusTrojan.Win32.Agent
FortinetW32/Agent.AAUV!tr
DeepInstinctMALICIOUS
alibabacloudBackdoor

How to remove Win32/Agent.AAUV?

Win32/Agent.AAUV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment