Gridinsoft Logo

Amd_ags_x64.dll Trojan Agent Analysis

Technical Analysis

File Name amd_ags_x64.dll
File Type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Scanner Version 1.0.248.174
Database Version 2026-06-15 20:00:14 UTC

Trojan.Win64.Agent.cl

Malware family: Agent

Trojan Agent malware disguises itself as legitimate software while performing unauthorized activities including data theft and providing remote system access to threat actors.
N/A
Detection Rate
19,456
File Size (bytes)
2026-06-15
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
98fd10d3b309f04c3c29b05c5a40a5d6
SHA1
ac21397cb51a67946a467d54f14c726e3c1a9098
SHA256
27d80885bb67e2ee97b225176797aa30d6f165f42ef98e3c8f703bf0d9c62b19
SHA512
7d21a384a43c63d8162666be62e4f896eeab13810aac807c806020c7572c2c74fbde6e55787082683a78c88e2dcbeca47a031a870699ba15452d62e6f04dec7d
ImpHash
32f5cbe63ba5c84834d3b248ba4f3590

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x1800014c0
Compilation Time 2026-05-13 17:14:25
Checksum 0x00000000 (Actual: 0x0000ba70)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 4 libraries
KERNEL32, ADVAPI32, ntdll, SHLWAPI
Exports 37 functions
Resources 0 Resources
Sections 5 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 7,974 bytes 8,192 bytes 6.23 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 51358F7DCCB0805BAC16283626AFFC55
.rdata 0x00003000 7,400 bytes 7,680 bytes 4.92 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 23516D2D8CA25F7B036EA5F159C963E5
.data 0x00005000 6,864 bytes 1,024 bytes 3.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E26EC4C64FEA6EF958CDE09C17EC8571
.pdata 0x00007000 600 bytes 1,024 bytes 2.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E133BEBB1418FD9D39589DA63F1FDFE7
.reloc 0x00008000 36 bytes 512 bytes 0.51 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ D84C9B48982AF471E787DA90F61E1932

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.Agent.cl Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.Agent.cl without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. 1
    Get Gridinsoft Anti-Malware — it's a quick 2 MB download that won't slow down your PC.
  2. 2
    Run the installer gsam-en-install.exe. The setup takes about 2 minutes and doesn't require a restart.
  3. 3
    The app launches right after installation. You'll see the main dashboard with the scan button front and center.
  4. 4
    Hit "Standard Scan" — this checks all the spots where malware typically hides: temp folders, browser data, startup programs, and system directories.
  5. 5
    Once the scan finds this threat, click "Clean Now". The removal usually happens instantly, though some stubborn infections may need a reboot.
  6. 6
    If you see a restart prompt, go ahead and reboot. This clears any malware that was running in memory and ensures your system starts fresh.
Important: Before You Start
Quick tip: unplug from the internet before scanning. Some malware phones home for instructions or downloads extra payloads when it senses trouble. If the infection is severe, boot into Safe Mode first — it limits what can run and makes cleanup easier.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware