Malware

Should I remove “Win32:GenMalicious-AGV [Trj]”?

Malware Removal

The Win32:GenMalicious-AGV [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:GenMalicious-AGV [Trj] virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Creates known SpyNet mutexes and/or registry changes.

Related domains:

2.tcp.ngrok.io

How to determine Win32:GenMalicious-AGV [Trj]?


File Info:

crc32: F61286FD
md5: 35bd0df9a23172b32b95c52483c6e7b1
name: 35BD0DF9A23172B32B95C52483C6E7B1.mlw
sha1: 55facca9aab24ecef5fda454abcb13a4d96e04be
sha256: 16475b2dabce04660e1f6127adf54827b7cf024f4cded92b9be6e07c85ae7a89
sha512: 39da000094c865d4f88ab222f51c15fb1fbdfa7fe16db6f2d543e48bc6938afa2a206a3e9ee9dc8907b21c8fdd0dbc6dade3a814522c3475e91414e67847bb93
ssdeep: 24576:V4lavt0LkLL9IMixoEgeaV9FSFj3MqBqMxQOKqDUTEn/QBYkuAq9MmCS:skwkn9IMHeaV9FmjBdDoThYuaPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Win32:GenMalicious-AGV [Trj] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Autoit.CLU
McAfeeTrojan-AutoIt.h
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderAIT:Trojan.Autoit.CLU
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitAIT:Trojan.Autoit.CLU
BaiduWin32.Trojan-Dropper.Autoit.l
CyrenW32/AutoIt.DR.gen!Eldorado
APEXMalicious
KasperskyTrojan.Win32.Bublik.elhu
Ad-AwareAIT:Trojan.Autoit.CLU
EmsisoftAIT:Trojan.Autoit.CLU (B)
F-SecureDropper.DR/AutoIt.Gen
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.35bd0df9a23172b3
SophosML/PE-A
AviraDR/AutoIt.Gen
Antiy-AVLGrayWare/Autoit.Execute.a
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataAIT:Trojan.Autoit.CLU (2x)
CynetMalicious (score: 100)
ALYacAIT:Trojan.Autoit.CLU
MAXmalware (ai score=80)
MalwarebytesMachineLearning/Anomalous.100%
ESET-NOD32multiple detections
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Autoit.AGV!tr
BitDefenderThetaAI:Packer.E952DB6B15
AVGWin32:GenMalicious-AGV [Trj]
Cybereasonmalicious.9a2317
AvastWin32:GenMalicious-AGV [Trj]
Qihoo-360HEUR/QVM10.1.83C2.Malware.Gen

How to remove Win32:GenMalicious-AGV [Trj]?

Win32:GenMalicious-AGV [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment