Malware

How to remove “Downloader.Win32.Agent.mfke”?

Malware Removal

The Downloader.Win32.Agent.mfke is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mfke virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.mfke?


File Info:

crc32: 25DC7A55
md5: 82613b23c27db8ed803dafa453810538
name: cie1931E889B2E59D90E6A087E8AEA1E7AE97E8BDAFE4BBB6E7AE80E58D95E79A84E889B2E59D90E6A087E8AEA1E7AE97E8B
sha1: d868f4981d47bfc5aa65f10f84e63a482e35ea24
sha256: 05a1e2b3abd5b8b41c3105e505191966ce2ea591bf52b45964fda80c0638a138
sha512: 3f83083ff6e32c8c117e5ad5fa94514d0dc678080b58075ad26e53c8e540d83abf17a6f677d2a3cf17fb0bfd88b6bf8c1269dde627a9b37c2bf6528d2cd2685f
ssdeep: 24576:jZS3FWMuOGFRJHPauFM7CNOdq/qaYNJbnpIDnL28MBZHjhdU:cWMuOJ8XOEC9h6it7H1dU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0310
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0310
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mfke also known as:

FireEyeGen:Variant.Graftor.699946
McAfeeArtemis!82613B23C27D
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005105151 )
K7GWAdware ( 005105151 )
Cybereasonmalicious.3c27db
Invinceaheuristic
SymantecML.Attribute.HighConfidence
AvastWin32:Adware-gen [Adw]
GDataWin32.Application.Agent.VLU175
Kasperskynot-a-virus:Downloader.Win32.Agent.mfke
AlibabaDownloader:Win32/Qjwmonkey.769f955e
ViRobotAdware.Qjwmonkey.1392664.B
RisingAdware.Downloader!1.BDCA (CLOUD)
Endgamemalicious (high confidence)
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
McAfee-GW-EditionArtemis!PUP
MaxSecureTrojan.Malware.121218.susgen
SophosGeneric PUA NI (PUA)
IkarusPUA.Qjwmonkey
CyrenW32/Adware.MOTB-3907
AviraADWARE/AD.QjwMonkey.kudtu
MAXmalware (ai score=99)
Antiy-AVLGrayWare/Win32.Qjwmonkey
MicrosoftPUA:Win32/Qjwmonkey
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mfke
VBA32BScope.Adware.Qjwmonkey
MalwarebytesAdware.Qjwmonkey
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Downloader.Win32.Agent.mfke?

Downloader.Win32.Agent.mfke removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment