Malware

Win32/Agent.ADVG removal guide

Malware Removal

The Win32/Agent.ADVG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ADVG virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Agent.ADVG?


File Info:

name: 27D5763CA2E201A9BB5E.mlw
path: /opt/CAPEv2/storage/binaries/aef7b009a56f1081e7059465d7de7ec8880229fd2a627737f15a6ca48666323d
crc32: 547573CF
md5: 27d5763ca2e201a9bb5e8b3ead7298f5
sha1: 19e196fc72f63ce4947c66b8847b9a8591c333cb
sha256: aef7b009a56f1081e7059465d7de7ec8880229fd2a627737f15a6ca48666323d
sha512: e87faee9fca54ad72f3527be0760c4130d01640d808f93f241018dc27dd58fd56c344f8853782546d6cc9b57b51babd50c59ad6f8da4d490f0668e6aa53aec03
ssdeep: 24576:8N+bPGUvbX8AdjI9Bahe/wz78RaiyhrbnC3OlKekN4srzEhbaLUCKWmRlsSmYTzC:8wyYjI9EheW7WaiUy3V6baLUCmRlnmYq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T112659D21FA08C0B7D09211B0916D6A7B95997A322BAF4CD3F7C05E6D01B52D2F235F6B
sha3_384: d3054c209ff62e4d262446877848f0dc23e3bc3742eea9067850640d3a10934b87a5381da1b0064de32ff35f9266ce70
ep_bytes: e8b2060000e97afeffff3b0d48e05600
timestamp: 2023-11-23 11:16:32

Version Info:

CompanyName: Epic Games
FileDescription: Easy Anti-Cheat Bootstrapper (EOS)
FileVersion: 1.6.0.0
InternalName: EACLauncher.exe
LegalCopyright: Copyright Epic Games, Inc.
OriginalFilename: EACLauncher.exe
ProductName: Easy Anti-Cheat Bootstrapper (EOS)
ProductVersion: 1.6.0
Translation: 0x0409 0x04b0

Win32/Agent.ADVG also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Heur.Mint.Zard.45
VIPREGen:Heur.Mint.Zard.45
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Mint.Zard.45
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.ADVG
CynetMalicious (score: 100)
APEXMalicious
KasperskyVHO:Trojan.Win32.Sdum.gen
BitDefenderGen:Heur.Mint.Zard.45
AvastWin32:MalwareX-gen [Trj]
RisingDownloader.Agent!1.D93C (CLASSIC)
EmsisoftGen:Heur.Mint.Zard.45 (B)
DrWebTrojan.MulDrop24.21273
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.27d5763ca2e201a9
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.920
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
GDataGen:Heur.Mint.Zard.45
AhnLab-V3Trojan/Win.Generic.R624285
BitDefenderThetaGen:NN.ZexaF.36792.Ev1@aiMRHYak
ALYacGen:Heur.Mint.Zard.45
VBA32BScope.TrojanPSW.RisePro
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.ADVG!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.c72f63
DeepInstinctMALICIOUS

How to remove Win32/Agent.ADVG?

Win32/Agent.ADVG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment