Trojan

What is “BAT/TrojanDownloader.Agent.OFD”?

Malware Removal

The BAT/TrojanDownloader.Agent.OFD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/TrojanDownloader.Agent.OFD virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics

How to determine BAT/TrojanDownloader.Agent.OFD?


File Info:

crc32: 4EB4EA08
md5: b17fed04ed85390158dbdef5eaa32fd0
name: B17FED04ED85390158DBDEF5EAA32FD0.mlw
sha1: 1e88757e1ef65599dbc96211d80436c8d9af94ae
sha256: f7f0e52a19a8bf280fa3ca0acac6fbef3c1b9af79f63767367a063a9fbc177c1
sha512: 7a25a267d36e6bd3a5cea180effa3a341c037ce7d00fffc86c0cb928d839b85cdbf4f0ee761ba913556c5c3327872708d5a91eda5c8664199c671f88a5f840c3
ssdeep: 12288:LtLXhDK08XqMAe+WjjQ3podztZVTVH04N4rWW8U:L/DKrqM2WIudtZM64rW9U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: FireZzZ
FileDescription: Activator WF X10.xx Installation
FileVersion: X10.xx
Comments:
CompanyName: FireZzZ
Translation: 0x0409 0x04e4

BAT/TrojanDownloader.Agent.OFD also known as:

BkavW32.AIDetect.malware2
K7AntiVirusUnwanted-Program ( 004b9c8e1 )
DrWebTrojan.Hosts.48291
ALYacTrojan.GenericKD.36494935
CylanceUnsafe
SangforTrojan.Win32.Caynamer.A
AlibabaTrojanDownloader:BAT/Generic.7808cc17
K7GWUnwanted-Program ( 004b9c8e1 )
Cybereasonmalicious.4ed853
CyrenW32/Trojan.URUT-4338
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/TrojanDownloader.Agent.OFD
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.36494935
MicroWorld-eScanTrojan.GenericKD.36494935
Ad-AwareTrojan.GenericKD.36494935
SophosGeneric PUA BO (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.gc
FireEyeGeneric.mg.b17fed04ed853901
EmsisoftTrojan.GenericKD.36494935 (B)
WebrootW32.Adware.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D22CDE57
GDataTrojan.GenericKD.36494935
AhnLab-V3Malware/Win32.Generic.R373196
McAfeeArtemis!B17FED04ED85
MAXmalware (ai score=85)
VBA32Trojan.Hosts
TrendMicro-HouseCallTROJ_GEN.R06CH0CCG21
FortinetAdware/Generic_PUA_BO
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwUB56cA

How to remove BAT/TrojanDownloader.Agent.OFD?

BAT/TrojanDownloader.Agent.OFD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment