Trojan

About “Trojan.Agent.FRWL” infection

Malware Removal

The Trojan.Agent.FRWL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FRWL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid

How to determine Trojan.Agent.FRWL?


File Info:

name: 6DF165F09F99C3997999.mlw
path: /opt/CAPEv2/storage/binaries/88e6254f4eb467273baa50555367bbda871c5539c2475608125d56f2a35e0fa3
crc32: B32DD4C9
md5: 6df165f09f99c3997999cbe226eaecbc
sha1: bd1d03041e149a9163d5f056b862d55197475f8f
sha256: 88e6254f4eb467273baa50555367bbda871c5539c2475608125d56f2a35e0fa3
sha512: 9c575a288582a18af89108e1af6444558c4fa668a88675c832d5720409593ba2f64b1873f18ef01c2a474b28c732a78fb710685c92edab92fdbc46a26aabc26f
ssdeep: 24576:P68aFqvenKjNvZKChpsqjnhMgeiCl7G0nehbGZpbD:P65FkenKjNvZKStDmg27RnWGj
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17A65F12233D4C837E26319B589B5D3B86A37BC32A834844B67D01BADDF75592CA35B07
sha3_384: ce0f7a4aa10ba35c0253a7a80888571c94730f9e0b730303064b26ce45ce63d42bf05bbdff90110b0d872ba2cb69a336
ep_bytes: e8fc9f0000e9a5feffffcccccccc8b4c
timestamp: 2013-03-29 20:46:41

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe® Flash® Player Update Service 11.7 r700
FileVersion: 11,7,700,169
LegalCopyright: Copyright © 1996 Adobe Systems Incorporated
LegalTrademarks: Adobe® Flash® Player
ProductName: Adobe® Flash® Player Update Service
ProductVersion: 11,7,700,169
Translation: 0x0409 0x04b0

Trojan.Agent.FRWL also known as:

BkavW32.AIDetect.malware1
DrWebWin32.Expiro.153
MicroWorld-eScanTrojan.Agent.FRWL
FireEyeGeneric.mg.6df165f09f99c399
McAfeeGenericRXRG-JJ!6DF165F09F99
ZillyaTrojan.Waldek.Win32.7021
K7AntiVirusVirus ( 0058c9f71 )
K7GWVirus ( 0058c9f71 )
Cybereasonmalicious.41e149
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Expiro.NDO
ClamAVWin.Trojan.Generic-6623035-0
KasperskyVHO:Trojan.Win32.Waldek.gen
BitDefenderTrojan.Agent.FRWL
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
Ad-AwareTrojan.Agent.FRWL
EmsisoftTrojan.Agent.FRWL (B)
McAfee-GW-EditionGenericRXRG-JJ!6DF165F09F99
SentinelOneStatic AI – Suspicious PE
SophosGeneric ML PUA (PUA)
IkarusTrojan.Patched
GDataTrojan.Agent.FRWL
JiangminTrojan.Generic.hemlj
Antiy-AVLTrojan/Generic.ASVirus.316
ArcabitTrojan.Agent.FRWL
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.FileInfector.R462218
ALYacTrojan.Agent.FRWL
VBA32Trojan.Sabsik.TE
APEXMalicious
MAXmalware (ai score=83)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FileInfector.C!tr
AVGWin32:FileInfector-C [Heur]

How to remove Trojan.Agent.FRWL?

Trojan.Agent.FRWL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment