Trojan

About “Trojan.Agent.CEAF” infection

Malware Removal

The Trojan.Agent.CEAF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CEAF virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.blockcypher.com
hjhqmbxyinislkkt.1j9r76.top

How to determine Trojan.Agent.CEAF?


File Info:

crc32: 719D8D30
md5: a9ac508c8d7af6939596f8c123113ad5
name: A9AC508C8D7AF6939596F8C123113AD5.mlw
sha1: 72ede22244a6815a605d07def92bc622c3d386fa
sha256: a2fe00507f2ed3b511097db106113c5e2fd0e9a389b61436252bbc93730f1cfb
sha512: ad0c15c05ba6c29f33d66dfd68544a5325a1f3eea24a75083ae016fb49a514ef0c896830d2355c55a62a6b24ec83bff485ded2c6c5b5db84a232b9ae2a81cd90
ssdeep: 6144:gCRn+s/pYBaVViIsA5YperEBjEw18qF2yRCE2HxO/:BnbYB8Vrb5YpL8uT2HE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.CEAF also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Sphinx.2
MicroWorld-eScanTrojan.Agent.CEAF
FireEyeGeneric.mg.a9ac508c8d7af693
CAT-QuickHealRansom.Exxroute.A3
McAfeeRansomware-FMJ!A9AC508C8D7A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005137001 )
BitDefenderTrojan.Agent.CEAF
K7GWTrojan ( 0050636e1 )
Cybereasonmalicious.c8d7af
BitDefenderThetaGen:NN.ZexaF.34590.omX@aCzm2Tli
CyrenW32/Ransom.DK.gen!Eldorado
SymantecPacked.Generic.493
APEXMalicious
AvastWin32:Filecoder-AZ [Trj]
ClamAVWin.Ransomware.Cerber-6162277-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/generic.ali2000010
NANO-AntivirusTrojan.Win32.Zerber.elriom
RisingRansom.Cerber!8.3058 (CLOUD)
Ad-AwareTrojan.Agent.CEAF
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Ransom.Lukitos.A@7etman
F-SecureHeuristic.HEUR/AGEN.1116787
BaiduWin32.Trojan.Kryptik.bjk
ZillyaTrojan.Kryptik.Win32.1083610
TrendMicroRansom_CERBER.F117BR
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dc
EmsisoftTrojan-Ransom.Cerber (A)
IkarusTrojan.Dalexis
JiangminTrojan.Spora.bk
AviraHEUR/AGEN.1116787
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Agent.CEAF
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Agent.CEAF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.R195522
Acronissuspicious
VBA32BScope.Backdoor.Tofsee
ALYacTrojan.Agent.CEAF
TACHYONRansom/W32.Cerber.238890
MalwarebytesRansom.Cerber
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FOOY
TrendMicro-HouseCallRansom_CERBER.F117BR
TencentMalware.Win32.Gencirc.10b6533a
YandexTrojan.GenAsa!TCKU31FdIgI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Kryptik.FSHI!tr
AVGWin32:Filecoder-AZ [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Filecoder.HxQBNwcA

How to remove Trojan.Agent.CEAF?

Trojan.Agent.CEAF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment