Malware

Win32/Injector.AGIP removal guide

Malware Removal

The Win32/Injector.AGIP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AGIP virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Injector.AGIP?


File Info:

name: 2AACED1D642F655F1B67.mlw
path: /opt/CAPEv2/storage/binaries/009ebb9999b144ca1be902eae1896f67136de2671e65c6bf9b285fb5932cfed5
crc32: FCB84924
md5: 2aaced1d642f655f1b672aa8db41315d
sha1: 11bd1f4b086a03e4f687138e65dc914b5e2ff45b
sha256: 009ebb9999b144ca1be902eae1896f67136de2671e65c6bf9b285fb5932cfed5
sha512: 1d26347b18b8886efca8d51bc5bd93bcfdfaf0e05beeaf47356a4abe884131d193b1f65a263f20351c4ce1d0ca0b8b1437599092def687663559b2cdc62f208d
ssdeep: 49152:04xat1moBHcOwimtZHt4xat1moBHcOwimtZHt4xat1moBHcOwimtZHt4xat1moBe:0yuYnNyuYnNyuYnNyuYn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18446F116F6F14437D1236EB8DC1F536CA8267E502D34648A3BE82D48AF39781753B29B
sha3_384: c15451996b88b098e6d142d0a9b02d9372a07a533dcbaedc949bbb9c3f8101e4f94cb01e89fe6f88fe0a958805eb896b
ep_bytes: 558becb9280000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Reader
FileVersion: 11.0.02.0
LegalCopyright: Copyright 1984-2012 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe Reader
ProductVersion: 11.0.02.0
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

Win32/Injector.AGIP also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Inject1.20583
MicroWorld-eScanGen:Variant.Zusy.339143
FireEyeGeneric.mg.2aaced1d642f655f
ALYacGen:Variant.Zusy.339143
CylanceUnsafe
K7AntiVirusTrojan ( 0056fa991 )
K7GWTrojan ( 0056fa991 )
Cybereasonmalicious.d642f6
BitDefenderThetaAI:Packer.D0ED8D2015
ESET-NOD32a variant of Win32/Injector.AGIP
TrendMicro-HouseCallTROJ_INJECTOR_GG310387.UVPM
KasperskyTrojan.Win32.Agent.xosy
BitDefenderGen:Variant.Zusy.339143
NANO-AntivirusTrojan.Win32.Agent.bxpihj
AvastWin32:Malware-gen
RisingTrojan.Generic@ML.94 (RDML:lKw8Z1LsWFhxLpLh2haVxQ)
Ad-AwareGen:Variant.Zusy.339143
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Injector.ag (v)
TrendMicroTROJ_INJECTOR_GG310387.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Zusy.339143 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126519
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASBOL.2E1B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.339143
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.R452130
McAfeeGenericR-JZR!2AACED1D642F
VBA32BScope.Malware-Cryptor.073
MalwarebytesMalware.AI.4143657371
APEXMalicious
TencentMalware.Win32.Gencirc.11bc1b74
YandexTrojan.GenAsa!rEgeUpWGMN0
IkarusTrojan.Win32.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.REEL!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Injector.AGIP?

Win32/Injector.AGIP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment