Malware

Application.Agent.KFR removal guide

Malware Removal

The Application.Agent.KFR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.KFR virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Application.Agent.KFR?


File Info:

name: C9315C9DC89C030D060B.mlw
path: /opt/CAPEv2/storage/binaries/bdb53339301977797eed690a7e6d9c5c19efdeeed7425fb69b95f530a31f7f03
crc32: 6346B6CC
md5: c9315c9dc89c030d060bca662919f019
sha1: a5e08eee09e75ab8a492a5554e1b41050205727e
sha256: bdb53339301977797eed690a7e6d9c5c19efdeeed7425fb69b95f530a31f7f03
sha512: 17a06f3218c2357e4a362e70d51a0a258b10ef1b98af538ed83aa800d495553055556e386c2ad342cfe09d89a106c012e8704e1446a17a106f6814d841d5d9e2
ssdeep: 12288:cndrWj9XIb39rlyuZYC3uqGAbFxOJSkBTqZs7cO91S1YfzKmNlg/MdQo0gnbttKB:cndGl7uPeC0f96uYVmNu/CX0gnfUEM5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17825237637C0C0BAE21E80352A59DFB62B61FC8167E1111727DABB1FBD3139A792114B
sha3_384: 7a94924072002994e87b83fd43fea77bf8110ba15d29d038b9954b4df290254ea459953ed4df9252d0f754e164cac432
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2014-03-29 09:42:03

Version Info:

Comments: 桌面日历
CompanyName:
FileDescription: 桌面日历
FileVersion: 1.0.1.1
InternalName: 桌面日历
LegalCopyright: (C)
ProductName: 桌面日历
ProductVersion: 1.0.1.1
Translation: 0x0804 0x03a8

Application.Agent.KFR also known as:

BkavW32.AIDetect.malware1
LionicAdware.NSIS.Xpyn.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Agent.KFR
FireEyeGeneric.mg.c9315c9dc89c030d
CAT-QuickHealTrojan.MauvaiseRI.S5245166
ALYacApplication.Agent.KFR
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/Convagent.9def0bb2
VirITTrojan.Win32.KillFiles.BQFE
CyrenW32/NSISMod.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.NSISmod.A suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CA622
ClamAVWin.Trojan.691128-1
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
BitDefenderApplication.Agent.KFR
NANO-AntivirusRiskware.Win32.ShouQu.dmnfjx
AvastWin32:Adware-gen [Adw]
Ad-AwareApplication.Agent.KFR
SophosGeneric PUA KF (PUA)
DrWebTrojan.KillFiles.28526
McAfee-GW-EditionBehavesLike.Win32.AdwareSuLang.dc
EmsisoftApplication.Agent.KFR (B)
GDataApplication.Agent.KFR
JiangminAdWare.NSIS.bqy
MAXmalware (ai score=75)
Antiy-AVLTrojan/Generic.ASBOL.8A95
GridinsoftRansom.Win32.Sabsik.sa
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!C9315C9DC89C
VBA32Adware.NSIS.Xpyn
MalwarebytesMalware.AI.2753447489
YandexTrojan.GenAsa!hrZneoTQ9ng
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.4685!tr
AVGWin32:Adware-gen [Adw]

How to remove Application.Agent.KFR?

Application.Agent.KFR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment