Malware

Win32/Agent.AWL removal guide

Malware Removal

The Win32/Agent.AWL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.AWL virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • CAPE detected the PoisonIvy malware family
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Agent.AWL?


File Info:

name: D66DE131BA407209BFC3.mlw
path: /opt/CAPEv2/storage/binaries/8389b16a23176741210eca6cb4ccfa6ae3948ece5fbaf78223d4141cf1d82ead
crc32: E0CAAB88
md5: d66de131ba407209bfc3d4d82787f59e
sha1: 0b4534c71e51cb3f5a974d5f462d196bc3834eaf
sha256: 8389b16a23176741210eca6cb4ccfa6ae3948ece5fbaf78223d4141cf1d82ead
sha512: 2f9a1f0e6f101f64acea1c0dacacd3f2b907424eb82d6b90049ffe9f837b882e9c8fab7be7d22d02fed9ce495bb5a5701383ab83243cf21e8d03a366e229c67e
ssdeep: 96:VauL+3O6lqPUDAS/sX83Zbe8HCN08jgMwR1rf3L49nBnp7ZVLsA2Gr6m:v+3O6lETF4bXHP8ER1fonBnpfx2c6m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196F10853FF2EC2C4F5411AB5135790FA8E65CA28416C78BBEE919E46C0CF563E938391
sha3_384: 2fc071b215b1d60a07b72edbd739217b5eb5746c4c72e7dc253ffce43ea24462a82a80e3eb24f55d1a33bce800d75605
ep_bytes: 81ece40c00005355568b352c20400057
timestamp: 2007-05-31 06:45:41

Version Info:

0: [No Data]

Win32/Agent.AWL also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Trojan.ExplorerHijack.amX@auNnXip
FireEyeGeneric.mg.d66de131ba407209
ALYacGen:Trojan.ExplorerHijack.amX@auNnXip
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3dd1 )
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.1ba407
CyrenW32/Threat-HLLSI-based!Maximus
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32Win32/Agent.AWL
APEXMalicious
KasperskyTrojan.Win32.Agent.awl
BitDefenderGen:Trojan.ExplorerHijack.amX@auNnXip
NANO-AntivirusTrojan.Win32.Agent.dqujno
AvastWin32:Hupigon-JCU [Trj]
Ad-AwareGen:Trojan.ExplorerHijack.amX@auNnXip
EmsisoftGen:Trojan.ExplorerHijack.amX@auNnXip (B)
ComodoTrojWare.Win32.Agent.AWL@3hh5
F-SecureTrojan.TR/Hijacker.Gen
DrWebBackDoor.IRC.Sdbot.3134
ZillyaTrojan.Agent.Win32.12176
TrendMicroTROJ_AGENT.GMM
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ExplorerHijack.amX@auNnXip
JiangminTrojan/Agent.kwz
AviraTR/Hijacker.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1DF82A
ArcabitTrojan.ExplorerHijack.E67BE8
ViRobotTrojan.Win32.Agent.19835
ZoneAlarmHEUR:Trojan.Win32.Invader
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
MAXmalware (ai score=85)
VBA32Trojan.Agent
TrendMicro-HouseCallTROJ_AGENT.GMM
RisingTrojan.Win32.Agent.awl (RDMK:cmRtazpIO/w2h5t0provs6RnvOS7)
YandexTrojan.GenAsa!EfZPAsdHiKg
MaxSecureTrojan.Malware.485003.susgen
BitDefenderThetaAI:Packer.B48196921E
AVGWin32:Hupigon-JCU [Trj]
PandaTrj/Vilsel.AF
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Agent.AWL?

Win32/Agent.AWL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment