Malware

Troj/Agent-AEMF removal tips

Malware Removal

The Troj/Agent-AEMF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-AEMF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Troj/Agent-AEMF?


File Info:

name: 025F41FC01A6F32615AE.mlw
path: /opt/CAPEv2/storage/binaries/1c706cab290fad7b2d48e877818ac8aabb2eaa407f5387440af6a53d073d48e1
crc32: 1FAE6C2D
md5: 025f41fc01a6f32615aeecd5c246f2eb
sha1: c6426445ba362e6417da92e0024ba21fe1ddfb5a
sha256: 1c706cab290fad7b2d48e877818ac8aabb2eaa407f5387440af6a53d073d48e1
sha512: 7a10e6dfd2c7ca1e9533959a40c2d14323049fdbb5a2617cf12ca48f658129e8d8c5aab8d092630f23b5efc0f1334ca2147ad900bbd1a5cd180a3f67aad77138
ssdeep: 768:2FS7CVMDJ5J3eXEcdgPvtYY7qk0nlfeKoS/0:2YjJ5EXEc2tHqk5KoJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10FC34BA2FB5D982DD2DB413710F6F0A6671B3FA03525909EFC8DB3791AB734264A081D
sha3_384: ebe329313ccbdaf88cba825695ffb348d236d71053217fd845e417494d69373640f427de1a14abe4790c7a9345244eed
ep_bytes: e8fe020000e959290000c3000cae976d
timestamp: 2013-10-30 10:59:03

Version Info:

0: [No Data]

Troj/Agent-AEMF also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Downloader.JQDW
FireEyeGeneric.mg.025f41fc01a6f326
SkyhighBehavesLike.Win32.PolyPatch.cz
McAfeePolyPatch-UPX
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Small.Win32.234055
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaGen:NN.ZexaF.36804.hmX@a4BDM5mi
SymantecDownloader.Upatre
ESET-NOD32Win32/TrojanDownloader.Small.AAB
ZonerTrojan.Win32.18885
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-Spy.Win32.Zbot.gen
BitDefenderTrojan.Downloader.JQDW
NANO-AntivirusTrojan.Win32.Zbot.cnamwx
AvastWin32:Upatre-E [Trj]
TencentMalware.Win32.Gencirc.10bfd6eb
EmsisoftTrojan.Downloader.JQDW (B)
BaiduWin32.Trojan-Downloader.Small.cc
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Downloader.JQDW
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
SophosTroj/Agent-AEMF
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.17H5W1I
JiangminTrojanSpy.Zbot.dxmt
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.AAL@5l06uw
ArcabitTrojan.Downloader.JQDW
ZoneAlarmVHO:Trojan-Spy.Win32.Zbot.gen
MicrosoftPWS:Win32/Zbot.AF!MTB
VaristW32/Upatre.SW.gen!Eldorado
AhnLab-V3Trojan/Win.Upatre.C5611628
Acronissuspicious
VBA32TrojanSpy.Zbot
ALYacTrojan.Downloader.JQDW
MAXmalware (ai score=88)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingTrojan.Agent!1.DF43 (CLASSIC)
IkarusTrojan-PWS.Win32.Fareit
MaxSecureTrojan.Upatre.Gen
FortinetW32/Zbot.QMSC!tr
AVGWin32:Upatre-E [Trj]
DeepInstinctMALICIOUS

How to remove Troj/Agent-AEMF?

Troj/Agent-AEMF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment