Malware

Win32/AutoRun.Agent.AGF removal

Malware Removal

The Win32/AutoRun.Agent.AGF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.Agent.AGF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key

How to determine Win32/AutoRun.Agent.AGF?


File Info:

name: D2F9EC16DFDDA102287B.mlw
path: /opt/CAPEv2/storage/binaries/6a84ae8e81a1e031e6fcd5391ad129c71853bdaa78ba8f4675c9511b99b5c5c3
crc32: 078E1145
md5: d2f9ec16dfdda102287b4c6c6a245980
sha1: 87978512c53010cf23f8eb125d868f8fd78695e2
sha256: 6a84ae8e81a1e031e6fcd5391ad129c71853bdaa78ba8f4675c9511b99b5c5c3
sha512: 43e40fd75747901ed1469ef19f6ede1184082a9d009395457f2ed7338a362239060f13f7f881afb94a100c4df09ab40545e56d213df0843b8bc1550847d6b34a
ssdeep: 3072:93A7Q2an7L3Phjjy4mrQV8ti/I7moI8Tv3uf2AWd0h3r0xGvs:9wkvHZjnVeFuI0h3wYvs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B047D06B685B531F12A2533007A87778B3ABC39273349CBBF9527B59A273C19F25316
sha3_384: 408e7dd20a8a135cf20087c6fcf909c9a2fee638e62a6912e921a34b20a290e9dd3563b76176900a30ba7fc94c1474e8
ep_bytes: e825930000e989feffff8bff558bec8b
timestamp: 2013-03-27 20:43:45

Version Info:

0: [No Data]

Win32/AutoRun.Agent.AGF also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Vresmon.Gen.1
FireEyeGeneric.mg.d2f9ec16dfdda102
McAfeeRDN/Autorun.worm!bh
CylanceUnsafe
VIPRETrojan.Win32.Reveton.a!ag (v)
K7AntiVirusP2PWorm ( 003c56621 )
AlibabaWorm:Win32/EncPk.f5781bc6
K7GWP2PWorm ( 003c56621 )
Cybereasonmalicious.6dfdda
BitDefenderThetaGen:NN.ZexaF.34212.luW@aaqVm7aG
VirITTrojan.Win32.Winlock.KLC
CyrenW32/Clisbot.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.Agent.AGF
TrendMicro-HouseCallWORM_CLISBOT.SMA
Paloaltogeneric.ml
ClamAVWin.Trojan.Ag-4254306-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Vresmon.Gen.1
NANO-AntivirusTrojan.Win32.Zbot.brmoah
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
AvastWin32:Carberp-AOR [Trj]
TencentMalware.Win32.Gencirc.10ba4d29
Ad-AwareGen:Trojan.Vresmon.Gen.1
TACHYONTrojan/W32.Jorik.182784.AE
EmsisoftGen:Trojan.Vresmon.Gen.1 (B)
ComodoTrojWare.Win32.Injector.AEMX@4wu5jp
DrWebTrojan.Winlock.7048
ZillyaTrojan.Jorik.Win32.210479
TrendMicroWORM_CLISBOT.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-R + Mal/EncPk-AGD
APEXMalicious
GDataGen:Trojan.Vresmon.Gen.1
JiangminTrojan/PornoAsset.rjo
WebrootW32.Malware.Gen
AviraWORM/Clisbot.182446
Antiy-AVLTrojan[Dropper]/Win32.Injector
KingsoftHeur.SSC.2681779.1216.(kcloud)
ArcabitTrojan.Vresmon.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Clisbot.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Clisbot.R59913
Acronissuspicious
VBA32TrojanDropper.Injector
ALYacGen:Trojan.Vresmon.Gen.1
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2725008386
RisingTrojan.Win32.Generic.148D6A94 (C64:YzY0OqJO1cuZzO/y)
YandexTrojan.GenAsa!Aw44IaZuWd4
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ZVR!tr
AVGWin32:Carberp-AOR [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/AutoRun.Agent.AGF?

Win32/AutoRun.Agent.AGF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment