Malware

Downloader.Win32.Agent.mffn (file analysis)

Malware Removal

The Downloader.Win32.Agent.mffn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mffn virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.mffn?


File Info:

crc32: 9DE6B6DF
md5: 88267fdbb69fc772b55e633384e384e4
name: edupep-n8508gs311_16907.exe
sha1: 8d2cdef48113c52491a02df23feace610e2d6b6a
sha256: 0a36f6634646b0c900ef1c5fb30f3c86d1c8beb3cb7035c65dfda22c5f5dd8cd
sha512: 5f8ad07a6cb7e0c8a6cd33f16f5aa1b4a8aa64a400c19c359e1daaee63df76fe7ffb9b928eeffefe3ff45c98381edc661caae636bd627a9cc5e023921ac47cdd
ssdeep: 24576:n31Y1pidrTOoFeyS140FodGZ5L+/Iw9WBJTgTMp/HnDds:61pi1yT1CdSiNWfZp/HDds
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0307
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0307
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mffn also known as:

MicroWorld-eScanGen:Variant.Johnnie.225567
FireEyeGen:Variant.Graftor.699946
McAfeeArtemis!88267FDBB69F
SangforMalware
K7AntiVirusAdware ( 005104d01 )
BitDefenderGen:Variant.Johnnie.225567
K7GWAdware ( 005104d01 )
Cybereasonmalicious.bb69fc
Invinceaheuristic
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
GDataGen:Variant.Johnnie.225567
Kasperskynot-a-virus:Downloader.Win32.Agent.mffn
AlibabaDownloader:Win32/Qjwmonkey.cc118687
ViRobotAdware.Qjwmonkey.1392664
AvastWin32:Adware-gen [Adw]
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Johnnie.225567 (B)
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA IN (PUA)
IkarusPUA.Qjwmonkey
CyrenW32/Adware.VDZP-6156
WebrootW32.Adware.Gen
AviraADWARE/AD.QjwMonkey.jkrfz
MAXmalware (ai score=99)
Antiy-AVLGrayWare[AdWare]/Win32.Qjwmonkey
MicrosoftPUA:Win32/Qjwmonkey
ArcabitTrojan.Johnnie.D3711F
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mffn
AhnLab-V3PUP/Win32.Installer.C4011793
VBA32BScope.Adware.Qjwmonkey
ALYacGen:Variant.Johnnie.225567
Ad-AwareGen:Variant.Johnnie.225567
MalwarebytesAdware.ChinAd
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R002H0CCC20
RisingAdware.Downloader!1.BDCA (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove Downloader.Win32.Agent.mffn?

Downloader.Win32.Agent.mffn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment