Malware

What is “Win32/Agent.ADVV”?

Malware Removal

The Win32/Agent.ADVV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ADVV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent.ADVV?


File Info:

name: 36B1113037D15DE46992.mlw
path: /opt/CAPEv2/storage/binaries/db7b5d8d3e83317dda251c54be0df6f4b6b90320969ec93eaab3554ae64cfe39
crc32: D57D3049
md5: 36b1113037d15de46992dd967140ee45
sha1: d93f996de885128a6a61cc1d8b9d643fc58dc44c
sha256: db7b5d8d3e83317dda251c54be0df6f4b6b90320969ec93eaab3554ae64cfe39
sha512: b41a0f36ef494a2a677f57464833268725ba8288022529a311a6ecf708d925695620e032b34719a862187ccedb6d9a4deb0ccfe13b2ac3bd4f2651c52ea41e0d
ssdeep: 6144:VWr41a+d+wXqNNobw5Ps/At/smyQTqAOLphldlYuHAGC2qS9tXhxAyi9WjEstTCg:6ik5UICETqFphlrF5qQ1AyiXWg2lvv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AC4B00176ADFCF2D072463157BFC3F15B3DF8110A69CAAF67840A1E4AAC1937A21B56
sha3_384: acec32a5fcb464bd8005335e01550906774e9aebc816e3e1c3377c34189ec029f62424fbf1473f020d9fcffbae46f94e
ep_bytes: e846060000e97afeffff3b0d68004400
timestamp: 2022-01-13 21:08:23

Version Info:

FileDescription: M1cr0
FileVersion: 1, 2, 0, 0
InternalName: M1cr0
LegalCopyright: Copyright (C) 2009 M1cr0
OriginalFilename: M1cr0.exe
ProductName: M1cr0
ProductVersion: 1, 2, 0, 0
Translation: 0x0409 0x04b0

Win32/Agent.ADVV also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Shellcode.3!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.39512
MicroWorld-eScanTrojan.GenericKD.48247244
FireEyeGeneric.mg.36b1113037d15de4
CAT-QuickHealTrojan.ShellcodeIH.S26231542
ALYacTrojan.GenericKD.48247244
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2630304
SangforExploit.Win32.Shellcode.gen
K7AntiVirusTrojan ( 0058d22d1 )
AlibabaExploit:Win32/Shellcode.aad0c132
K7GWTrojan ( 0058d22d1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34182.Jy0@aitjn9bi
CyrenW32/Dridex.GK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ADVV
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderTrojan.GenericKD.48247244
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingExploit.Shellcode!8.2A (C64:YzY0OliWflAdonyj)
TACHYONTrojan/W32.Agent.574464.CN
SophosMal/Generic-S
ComodoMalware@#zemlgif2elbr
TrendMicroTROJ_GEN.R002C0PAH22
McAfee-GW-EditionBehavesLike.Win32.Packed.hc
EmsisoftTrojan.GenericKD.48247244 (B)
Paloaltogeneric.ml
JiangminExploit.ShellCode.ftc
AviraTR/Crypt.ZPACK.Gen9
Antiy-AVLTrojan/Generic.ASMalwS.350BBD9
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftExploit:Win32/ShellCode!ml
GDataWin32.Trojan.PSE.1YXVC1H
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.HV.R465391
McAfeeGenericRXRM-MA!36B1113037D1
MAXmalware (ai score=85)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesMalware.AI.598294510
TrendMicro-HouseCallTROJ_GEN.R002C0PAH22
TencentMalware.Win32.Gencirc.10cff8c2
YandexTrojan.Kryptik_AGen!Xe6b97rou2w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74214920.susgen
FortinetW32/Kryptik_AGen.PQ!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.de8851
PandaTrj/GdSda.A

How to remove Win32/Agent.ADVV?

Win32/Agent.ADVV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment