Trojan

Should I remove “Trojan.AgentVMF.S25436583”?

Malware Removal

The Trojan.AgentVMF.S25436583 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentVMF.S25436583 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Trojan.AgentVMF.S25436583?


File Info:

name: F1EAF991101D76127AF9.mlw
path: /opt/CAPEv2/storage/binaries/fbc8d609a59110ad0b02f70c3b069d392e8860688c522c78b3bc9c41f845d0b8
crc32: A0DC0797
md5: f1eaf991101d76127af998f985629536
sha1: f239a5026d80a3823bfedf5bbab968d78a14c897
sha256: fbc8d609a59110ad0b02f70c3b069d392e8860688c522c78b3bc9c41f845d0b8
sha512: a983e1c1f84719acd2bb02af8b7c7c8cf16b8b78632dbbf5d557e7e3183a7b378fd07b45eb753c5b872d9551c58da31471d8fd37e69df74770ae01b969b5419b
ssdeep: 24576:+jjcX4aPBHkuc5PHY64X5spOST31HpJU3vz5SZGn24sn:xX4KcVZp6LvU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D258206F620D51DE44280F4BD99DA967A546CF20288B817F782EF4972B13E7ADF470B
sha3_384: a3b412136ad4047fd616356ec03971367e662543aae456bf386cbb7018581e17313bd0ead2705a473c84b84ce1fd4d05
ep_bytes: 6864a64000e8eeffffff000000000000
timestamp: 2016-07-20 15:42:59

Version Info:

Translation: 0x0409 0x04b0
CompanyName: znwqzq
ProductName: nyopsu
FileVersion: 1.00
ProductVersion: 1.00
InternalName: a
OriginalFilename: a.exe

Trojan.AgentVMF.S25436583 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.MLT.1
FireEyeGeneric.mg.f1eaf991101d7612
CAT-QuickHealTrojan.AgentVMF.S25436583
McAfeeGenericRXPH-LD!F1EAF991101D
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWNetWorm ( 700000151 )
K7AntiVirusNetWorm ( 700000151 )
BitDefenderThetaAI:Packer.F6F51DD920
VirITTrojan.Win32.VB_Heur
ESET-NOD32a variant of Win32/Spy.Bancos.AAO
ClamAVWin.Trojan.Dialog-9873788-0
KasperskyTrojan.Win32.Agent.newsnv
BitDefenderGen:Heur.PonyStealer.MLT.1
AvastWin32:GenMalicious-XO [Trj]
TencentMalware.Win32.Gencirc.10cf9d48
Ad-AwareGen:Heur.PonyStealer.MLT.1
EmsisoftGen:Heur.PonyStealer.MLT.1 (B)
ComodoTrojWare.Win32.TrojanSpy.Bancos.KHO@5rvpl2
DrWebTrojan.DownLoader22.21183
VIPRELooksLike.Win32.Malware!vb (v)
McAfee-GW-EditionGenericRXPH-LD!F1EAF991101D
SophosMal/Generic-S
APEXMalicious
GDataGen:Heur.PonyStealer.MLT.1
JiangminTrojan.Agent.ahou
AviraTR/ATRAPS.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.1A253AD
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Cossta.R218005
VBA32Trojan.Agent
ALYacGen:Heur.PonyStealer.MLT.1
MAXmalware (ai score=87)
MalwarebytesMalware.AI.1930929639
RisingSpyware.Bancos!8.2F8 (C64:YzY0Ovc2gzBPARRk)
YandexTrojan.GenAsa!mK1fh9obrmo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Bancos.ACMB!tr
AVGWin32:GenMalicious-XO [Trj]
PandaTrj/Genetic.gen

How to remove Trojan.AgentVMF.S25436583?

Trojan.AgentVMF.S25436583 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment