Malware

How to remove “Win32/AutoRun.Agent.TG”?

Malware Removal

The Win32/AutoRun.Agent.TG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AutoRun.Agent.TG virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Starts servers listening on 0.0.0.0:45442
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Sniffs keystrokes
  • Attempts to stop active services
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

www.showmyipaddress.com
whatismyipaddress.com
whatismyip.everdot.org
www.whatismyip.com
www.whatismyip.ca
www.wikipedia.org
pmqyiytmmx.info
igjxzspbqflv.info
kqicoiiuwysa.org
dhrygxzcupaw.info
lsvalekua.com
sucueios.org
pbeiiz.net
soxwuuct.info
ioaqcwma.com
amycmecs.com
dihdfwr.info
qscuwesy.org
cljxckoe.net
ocwwkyewgyyq.com
auvpkazrjyzd.net
cwsysg.com
spqmuqyn.info
hkqogkalw.info
duyszugzuwgr.info
dhrmxrro.info
tatljckuj.org
wevadwrd.info
dibytctkd.com
vohnqq.net
zsrrov.info
zbvnzihyfg.net
sagqftyqryz.net
qckgsccy.com
isgwanr.net
eygiowgqsc.org
qchbblup.net
prfgrqxst.info
iypezdrnzpjn.net
tiomxjrsbakk.net
rmnkuij.net
nowbzzrqayw.info
eomuma.org
fglkgo.net
ieoiio.org
jqdqruagm.com
yujqjwkgk.info
sylsjwz.net
tdtcggnotia.info
gizkdjpwuet.net
syiyywcmwc.org
ocxqvuvzw.info
twdphkf.com
hrgkrcc.com

How to determine Win32/AutoRun.Agent.TG?


File Info:

crc32: C050E01B
md5: 5b9b7788b7c273ad7d4b92303ba8e5c2
name: 5B9B7788B7C273AD7D4B92303BA8E5C2.mlw
sha1: 8de28329bbe14024385f31dc0275f03cbeb52a5e
sha256: 157d52bea002de7d18c5373b83aaf0bb327ce48d942a7ec7a68421663ef664ab
sha512: 7a07fe620e4a3774a255e212c1ea4cee8d76c3555fb36048f7914e730aac8b628cac038aeb32aca7c6e30f83d3fc6b8cb72f1b60bba076a5b781f3a06abafd29
ssdeep: 6144:b3ue8ySm8hQAAIfFrRXuEE+0l97mKwK/qHVNsV86JQPDHDdx/Qtqa:x/zkFF+EExZmKb/uVNEPJQPDHvd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/AutoRun.Agent.TG also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Pykspa.1
FireEyeGeneric.mg.5b9b7788b7c273ad
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Pykspa.1
CylanceUnsafe
VIPREWorm.Win32.Skyper.b (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003da8d71 )
BitDefenderGen:Variant.Pykspa.1
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.8b7c27
BitDefenderThetaGen:NN.ZexaF.34590.unW@aeWPeek
CyrenW32/Risk.BZSN-6837
SymantecW32.Pykspa.D
TotalDefenseWin32/Vilsel.CE
BaiduWin32.Worm.Autorun.o
APEXMalicious
AvastWin32:Renos-KY [Trj]
ClamAVWin.Worm.Pykspa-1
KasperskyTrojan-Ransom.Win32.Blocker.jcen
NANO-AntivirusTrojan.Win32.Agent.ctkmgw
ViRobotTrojan.Win32.Blocker.Gen.B
RisingWorm.Autorun!1.BC87 (RDMK:cmRtazoBN+Sq8PdOq/H60qt/cfOn)
Ad-AwareGen:Variant.Pykspa.1
EmsisoftGen:Variant.Pykspa.1 (B)
ComodoWorm.Win32.Autorun.Agent_TG0@1isiwy
F-SecureTrojan-Downloader:W32/Renos.gen!T
DrWebTrojan.Siggen.36621
ZillyaTrojan.Vilsel.Win32.2602
TrendMicroWORM_VILSEL.SMC
McAfee-GW-EditionBehavesLike.Win32.Pykse.tz
SophosML/PE-A + W32/Pykse-F
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.lhz
MaxSecureTrojan.Ransom.Blocker.iprw
AviraTR/Agent.327680.A
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.AntiAV
KingsoftHeur.SSC.2452.1216.(kcloud)
MicrosoftWorm:Win32/Pykspa.C
ArcabitTrojan.Pykspa.1
SUPERAntiSpywareWorm.SkypeBot
ZoneAlarmTrojan-Ransom.Win32.Blocker.jcen
GDataWin32.Trojan.PSE.KF4I2L
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zepfod.R4378
Acronissuspicious
McAfeeW32/Pykse.worm.gen.a
TACHYONRansom/W32.Blocker.1380352
VBA32Trojan.ChidikSun.28205
MalwarebytesGeneric.Worm.Agent.DDS
PandaTrj/Vilsel.B
ZonerTrojan.Win32.24407
ESET-NOD32Win32/AutoRun.Agent.TG
TrendMicro-HouseCallWORM_VILSEL.SMC
TencentWorm.Win32.Pykspa.a
YandexTrojan.GenAsa!R41E4MI3PTc
IkarusTrojan.Win32.AntiAV
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.XEK!tr
WebrootW32.Trojan.Vilsel.Gen
AVGWin32:Renos-KY [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Worm.Win32.Pykse.A

How to remove Win32/AutoRun.Agent.TG?

Win32/AutoRun.Agent.TG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment