Malware

Downloader.Win32.Agent.mfwd malicious file

Malware Removal

The Downloader.Win32.Agent.mfwd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mfwd virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.mfwd?


File Info:

crc32: EA49527D
md5: 0310f0303a731eea17639beff549406b
name: adobecreativesuitecleanertooladobeE58DB8E8BDBDE6B885E79086E5B7A5E585B7formacv6.0E88BB9E69E9CE794B5E8
sha1: 43c8629351a9671e67a9ab0e500820399531213e
sha256: b34ca2054d8bc61b6efdbc447a56e9f6602f0c6469d8b5f155a0d970450b9d5e
sha512: 661d52886ea2bc5d8e5cca5abb3c320fa49506aed508e47bedb4f7a01797e1f752e4118134cc7b80a40370eb6f7a0ee8443c22956b5e2c5f0e89c41e18a49a29
ssdeep: 24576:FN3LLyVmYnUWmqpPjAqqKaXSpKkxLcsptGHRJImnU5c0ufdsJ:FN/YnJP5cSpbaZBEc06dsJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0317
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0317
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mfwd also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ulise.103394
FireEyeGeneric.mg.0310f0303a731eea
ALYacGen:Variant.Ulise.103394
MalwarebytesAdware.Qjwmonkey
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005105151 )
BitDefenderGen:Variant.Ulise.103394
K7GWAdware ( 005105151 )
Cybereasonmalicious.03a731
Invinceaheuristic
CyrenW32/Adware.TKIW-1680
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallPUA.Win32.WebaltaToolbar.B
Paloaltogeneric.ml
GDataGen:Variant.Ulise.103394
Kasperskynot-a-virus:Downloader.Win32.Agent.mfwd
AlibabaDownloader:Win32/Qjwmonkey.16ead4e6
ViRobotAdware.Qjwmonkey.1395216.A
RisingAdware.Downloader!1.BDCA (CLASSIC)
Ad-AwareGen:Variant.Ulise.103394
SophosGeneric PUA ED (PUA)
ComodoApplicUnwnt@#1qwmurpkbujty
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
ZillyaAdware.Qjwmonkey.Win32.628
TrendMicroPUA.Win32.WebaltaToolbar.B
McAfee-GW-EditionArtemis!PUP
EmsisoftGen:Variant.Ulise.103394 (B)
F-ProtW32/S-a35dbdc9!Eldorado
JiangminDownloader.Agent.myl
eGambitUnsafe.AI_Score_100%
AviraADWARE/AD.QjwMonkey.ghjml
MAXmalware (ai score=99)
Antiy-AVLRiskWare[Downloader]/Win32.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D193E2
SUPERAntiSpywareAdware.Qjwmonkey/Variant
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mfwd
MicrosoftPUA:Win32/Qjwmonkey
AhnLab-V3PUP/Win32.Installer.C4021483
McAfeeArtemis!0310F0303A73
VBA32BScope.Adware.Qjwmonkey
CylanceUnsafe
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TencentMalware.Win32.Gencirc.10b91d87
YandexPUA.Qjwmonkey!
IkarusPUA.Qjwmonkey
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qjwmonkey.KD!tr
WebrootW32.Adware.Gen
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen

How to remove Downloader.Win32.Agent.mfwd?

Downloader.Win32.Agent.mfwd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment