Malware

Should I remove “Downloader.Win32.Agent.mfuq”?

Malware Removal

The Downloader.Win32.Agent.mfuq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mfuq virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.mfuq?


File Info:

crc32: 9085E083
md5: de75d00867fb122f7361d9bbaa9d9b9b
name: E69893E4BFA1E794B5E88491E78988_1554_428297.exe
sha1: 6c016fc575c066aa26ed5ab0a1af72f53f6f0a03
sha256: e47a9d795d8e8d8d9cd77732a0673e4a90af21489cd6af2d49e6d6948897546b
sha512: ddd8eefffb0d1ff8bf7e26d56be844249290b6317ad02cf26307ee4dc27548377b87ed7786f873571b7e8c18fcc446ac4149ba2295467f0cc8c777db9482ab63
ssdeep: 24576:dZS3FWMuOGFRJHPauFM7CNOdq/qaYNJbnpIDnL28MBZHjhdU:SWMuOJ8XOEC9h6it7H1dU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0310
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0310
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mfuq also known as:

MicroWorld-eScanGen:Variant.Johnnie.225567
McAfeeArtemis!DE75D00867FB
ALYacGen:Variant.Johnnie.225567
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 005105151 )
BitDefenderGen:Variant.Johnnie.225567
K7GWAdware ( 005105151 )
Cybereasonmalicious.867fb1
F-ProtW32/S-9ae944ef!Eldorado
AvastWin32:Adware-gen [Adw]
GDataGen:Variant.Johnnie.225567
Kasperskynot-a-virus:Downloader.Win32.Agent.mfuq
AlibabaAdWare:Win32/Qjwmonkey.60b5e15a
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Johnnie.225567 (B)
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
MaxSecureTrojan.Malware.121218.susgen
FireEyeGeneric.mg.de75d00867fb122f
SophosGeneric PUA GM (PUA)
IkarusPUA.Qjwmonkey
CyrenW32/S-9ae944ef!Eldorado
WebrootW32.Adware.Gen
AviraADWARE/AD.QjwMonkey.kudtu
Antiy-AVLGrayWare/Win32.Qjwmonkey
ArcabitTrojan.Johnnie.D3711F
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mfuq
MicrosoftPUA:Win32/Qjwmonkey
VBA32BScope.Adware.Qjwmonkey
MAXmalware (ai score=80)
Ad-AwareGen:Variant.Johnnie.225567
MalwarebytesAdware.Qjwmonkey
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R002H0CCH20
RisingAdware.Downloader!1.BDCA (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGWin32:Adware-gen [Adw]

How to remove Downloader.Win32.Agent.mfuq?

Downloader.Win32.Agent.mfuq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment