Malware

Win32/Agent.AGEV removal guide

Malware Removal

The Win32/Agent.AGEV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.AGEV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • CAPE detected the shellcode get eip malware family
  • Attempts to execute suspicious powershell command arguments
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Agent.AGEV?


File Info:

name: 9238449016ECD5AE5CAA.mlw
path: /opt/CAPEv2/storage/binaries/931cdd159ac06c0095f5529180087d553fa0a639f1ca40091aa66755e72d9267
crc32: 0D272077
md5: 9238449016ecd5ae5caae441ca07c393
sha1: afb4bd2015699299adb9fb0da974f3327eaa0874
sha256: 931cdd159ac06c0095f5529180087d553fa0a639f1ca40091aa66755e72d9267
sha512: 391631f3bf52bafc5ca36a05af1ddc6cb839906b0563d60b72b3b764128c06693358d9d36bd7611e377eef6c6e53614d987d6966c66dcbc6904fa490f14077d1
ssdeep: 3072:HoSl4V/PBo3cSNN2IhNBQ9tdjqmJ/kFgykfR5Vzm7Xv6:Hoc4JOsSH2I1QX8m/JPVzG
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1DCC31207976D16BAF4D2677BC8A1E820C9EECC8E36F4A2C24E656C4B571D40F87661C3
sha3_384: 70477af3cd5914f8a9a33774acec9bbe8d2324233d20bc563062806da9b07f2287af5c765b711c229a3177fa1c8f45db
ep_bytes: 807c2408010f850502000060be009002
timestamp: 2023-09-16 05:46:15

Version Info:

0: [No Data]

Win32/Agent.AGEV also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.72531239
FireEyeTrojan.GenericKD.72531239
SkyhighBehavesLike.Win32.BadFile.cc
McAfeeArtemis!9238449016EC
SangforTrojan.Win32.Save.a
K7GWTrojan ( 005b190d1 )
K7AntiVirusTrojan ( 005b190d1 )
Paloaltogeneric.ml
ESET-NOD32a variant of Win32/Agent.AGEV
BitDefenderTrojan.GenericKD.72531239
TencentWin32.Trojan.Agent.Dkjl
EmsisoftTrojan.GenericKD.72531239 (B)
F-SecureTrojan.TR/Agent.uqogv
SophosMal/Generic-S
WebrootW32.Infostealer.Dridex
AviraTR/Agent.uqogv
MicrosoftTrojan:Win32/Leonem
ArcabitTrojan.Generic.D452BD27
GDataTrojan.GenericKD.72531239
CynetMalicious (score: 100)
RisingTrojan.Agent!8.B1E (CLOUD)
MAXmalware (ai score=80)
FortinetW32/Agent.AGEV!tr
alibabacloudTrojan:Win/Agent.AUMT

How to remove Win32/Agent.AGEV?

Win32/Agent.AGEV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment