Trojan

Trojan.Downloader.Agent.AAFY (file analysis)

Malware Removal

The Trojan.Downloader.Agent.AAFY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.Agent.AAFY virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan.Downloader.Agent.AAFY?


File Info:

name: 526846B64012C46092D6.mlw
path: /opt/CAPEv2/storage/binaries/0f66e95d0e11507dd9953cfff3d3ea52c5020f7ccde94f451b7e85cc4e6e3fc7
crc32: 5895E833
md5: 526846b64012c46092d6bf1fdaa1e3fe
sha1: 1980d1da878022b7a9da1510d96784f2e6a2987a
sha256: 0f66e95d0e11507dd9953cfff3d3ea52c5020f7ccde94f451b7e85cc4e6e3fc7
sha512: 69841c54904d6cebf994506b302d23e67cd63089ecce6f118d72efa89d8a629b7a0c8f269ea75b37fbda60cd16f669c6c5468b8479f55aed1eba17ebbe31a61f
ssdeep: 3072:v+yGX4gTo0KzKfuMqXVz+yGXl+yGXl+yGXI:mbIuo3XVCb4b4b4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D1439117A618851E3654B30AA29E2B59AB6BC7939B4E68FE73C3D3D1C315078C6331F
sha3_384: 3cd5b1c4dd34d2b4fdd295c2ced696940224b96655d86cbad3248db6ae89158e8cfc3c194807c47c0b058dd7868203fb
ep_bytes: 558bec6aff683845400068ac31400064
timestamp: 2009-01-08 03:20:21

Version Info:

0: [No Data]

Trojan.Downloader.Agent.AAFY also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.HLLO.Blop.7
MicroWorld-eScanTrojan.Downloader.Agent.AAFY
FireEyeGeneric.mg.526846b64012c460
CAT-QuickHealW32.Lamer.gen
SkyhighBehavesLike.Win32.Generic.dt
McAfeegeneric!bg
ZillyaDownloader.Agent.Win32.329190
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Lamer.5ddb4e73
K7GWTrojan-Downloader ( 0055e3da1 )
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderThetaAI:Packer.D58099FD1F
VirITTrojan.Win32.Agent.ATGG
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Agent.OQJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Lamer.e
BitDefenderTrojan.Downloader.Agent.AAFY
NANO-AntivirusTrojan.Win32.Agent.okin
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.Lamer.e
EmsisoftTrojan.Downloader.Agent.AAFY (B)
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.Downloader.Agent.AAFY
Trapminesuspicious.low.ml.score
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Agentb.g
VaristW32/Trojan.YVRO-3033
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
KingsoftWin32.Infector.xd.118303
XcitiumTrojWare.Win32.TrojanDropper.Mudrop.H@1cukoj
ArcabitTrojan.Downloader.Agent.AAFY
ZoneAlarmVirus.Win32.Lamer.e
GDataTrojan.Downloader.Agent.AAFY
GoogleDetected
AhnLab-V3Win-Trojan/Muldrop.Gen
ALYacTrojan.Downloader.Agent.AAFY
Cylanceunsafe
PandaTrj/Genetic.gen
RisingHarm.Win32.Agent.dp (CLASSIC)
IkarusTrojan.Dropper
FortinetW32/Mudrop.GFO!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.64012c
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Lamer.e

How to remove Trojan.Downloader.Agent.AAFY?

Trojan.Downloader.Agent.AAFY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment