Malware

Win32/Injector.AGDG malicious file

Malware Removal

The Win32/Injector.AGDG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AGDG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Injector.AGDG?


File Info:

name: 7D4563E46A5C90417584.mlw
path: /opt/CAPEv2/storage/binaries/cf57d7cc319c802652ba8cb02383db61fd6661b19a862da6b88013ca3fbcf025
crc32: 76BCE348
md5: 7d4563e46a5c90417584c23e861916a8
sha1: 3b540d642ada09ff5de8c946353bd59d169f727e
sha256: cf57d7cc319c802652ba8cb02383db61fd6661b19a862da6b88013ca3fbcf025
sha512: b80eb5a110ee0f8daa8168be87b6e35ec65d916f04d096ed13c399d570b4a2786d94d6de8d843edf554c2933c424771ec9afbe35b8dfb905ebdbab72dd45aa38
ssdeep: 3072:rCrGnNOu3ap01kqMTue7gNbVB/rB78TFTHugCoReiVWeJfefVUxj:rCIKp+kqKt7gZ3qTFbIyVWeU2xj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA34D029AF46C8A2F39676B047D36CA197E05D310A00905B95E2BD7F743470BBAD6B23
sha3_384: 63d49ee26e1f4cf478600a46c566f86a8cdb27a6d86685c2a0285654e8b7d5e80f0cfe8b0a4792adfc1aa779075bede4
ep_bytes: 64a1000000005589e56aff681c604000
timestamp: 2013-05-06 06:19:43

Version Info:

0: [No Data]

Win32/Injector.AGDG also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Redirect.154
MicroWorld-eScanTrojan.GenericKDZ.94580
FireEyeGeneric.mg.7d4563e46a5c9041
SkyhighBehavesLike.Win32.Generic.dm
McAfeePolyPatch-UPX
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004d4f221 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D17174
BitDefenderThetaGen:NN.ZexaF.36680.pmW@am!QSpgi
SymantecInfostealer
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Injector.AGDG
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ShipUp.ixmg
BitDefenderTrojan.GenericKDZ.94580
NANO-AntivirusTrojan.Win32.Redirect.cqjqga
AvastWin32:Gepys-F [Trj]
TencentTrojan.Win32.Shipup.kj
EmsisoftTrojan.GenericKDZ.94580 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan.Injector.jn
TrendMicroTROJ_AGENT_058153.TOMB
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.hrbgd
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.Toga.C@7tr8p9
MicrosoftTrojanDropper:Win32/Gepys.A
ZoneAlarmTrojan.Win32.ShipUp.ixmg
GDataWin32.Trojan.PSE.1JXVNT5
VaristW32/Kryptik.KYV.gen!Eldorado
AhnLab-V3Trojan/Win.Krypto.R591838
VBA32SScope.Malware-Cryptor.Carberp.2313
ALYacTrojan.GenericKDZ.94580
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_058153.TOMB
RisingTrojan.Injector!1.A765 (CLASSIC)
YandexTrojan.GenAsa!R1YGpcfwID0
IkarusTrojan-Downloader.Win32.Dofoil
FortinetW32/Kryptik.AYTT!tr
AVGWin32:Gepys-F [Trj]
Cybereasonmalicious.42ada0
DeepInstinctMALICIOUS

How to remove Win32/Injector.AGDG?

Win32/Injector.AGDG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment