Trojan

Trojan.Downloader.ciWfau8uKSeG information

Malware Removal

The Trojan.Downloader.ciWfau8uKSeG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.ciWfau8uKSeG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Downloader.ciWfau8uKSeG?


File Info:

name: 2FF53586010ADB6185E2.mlw
path: /opt/CAPEv2/storage/binaries/acc460bc8832d01634eac7e6f75b733018fecba2af8384986f1e7b06c540e2d8
crc32: 38BB33E1
md5: 2ff53586010adb6185e266e7e4d5fd4e
sha1: d1be8fb01ec64ecd6e0bb4465d54c11c37ad399f
sha256: acc460bc8832d01634eac7e6f75b733018fecba2af8384986f1e7b06c540e2d8
sha512: 533685402c8daa0d96c6bca9d9c30e75dea6c534b4125c4b1e314ad45158631afd909d9611dd63850322b8cad27a333d24b8fcb2c101c9209f16c4bfe05816f2
ssdeep: 768:vcACcKCbFq0s0r6XF1i2mahG+XlHSuJKqyLohQtx5:RKCxq0s0r6XFlm+VHTJKqOdr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10F236C92EF088647D0CCD63484B19F5873B6AC27B9775E1C11A07C96EEF1382172A9BD
sha3_384: 1c73506b4ad833cd6b64d5e2bbf36c89b18dbf71cabfcf6be8de9b88ed7923e5777c26b610978bb26c307b84398dff3b
ep_bytes: b858cd41005064ff3500000000648925
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Downloader.ciWfau8uKSeG also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Banload.a!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.2ff53586010adb61
SkyhighBehavesLike.Win32.ExploitMydoom.ph
McAfeeArtemis!2FF53586010A
Cylanceunsafe
ZillyaDownloader.Banload.Win32.18614
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f8b51 )
AlibabaTrojanDownloader:Win32/Banload.7e613529
K7GWTrojan ( 0040f8b51 )
BitDefenderThetaAI:Packer.81E6F5211C
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.QDS
APEXMalicious
AvastWin32:Evo-gen [Trj]
ClamAVWin.Trojan.Packed-94
KasperskyTrojan-Downloader.Win32.Banload.cbr
BitDefenderGen:Trojan.Downloader.ciWfau8uKSeG
NANO-AntivirusTrojan.Win32.Banload.vmxt
MicroWorld-eScanGen:Trojan.Downloader.ciWfau8uKSeG
TencentWin32.Trojan-Downloader.Banload.Timw
EmsisoftGen:Trojan.Downloader.ciWfau8uKSeG (B)
F-SecureTrojan.TR/Dldr.Delphi.Gen
DrWebTrojan.DownLoader.23802
VIPREGen:Trojan.Downloader.ciWfau8uKSeG
TrendMicroMal_Banker
Trapminemalicious.high.ml.score
SophosMal/DelpDldr-C
IkarusTrojan.Win32.Agent
JiangminTrojanDownloader.Banload.bur
VaristW32/Trojan.SOBC-8525
AviraTR/Dldr.Delphi.Gen
Antiy-AVLTrojan[Downloader]/Win32.Delf
KingsoftWin32.HeurC.KVM007.a
MicrosoftTrojan:Win32/Vindor!pz
XcitiumMalware@#342zdwxvm543c
ArcabitTrojan.Downloader.ciWfau8uKSeG
ViRobotTrojan.Win.Z.Banload.47104.A
ZoneAlarmTrojan-Downloader.Win32.Banload.cbr
GDataGen:Trojan.Downloader.ciWfau8uKSeG
GoogleDetected
AhnLab-V3Trojan/Win32.Banload.R41470
VBA32TScope.Trojan.Delf
ALYacGen:Trojan.Downloader.ciWfau8uKSeG
MalwarebytesMalware.Heuristic.2014
PandaTrj/Nabload.ACN
TrendMicro-HouseCallMal_Banker
RisingTrojan.DL.Win32.Banload.cbr (CLASSIC)
YandexTrojan.GenAsa!/zGBdD8F1lc
MAXmalware (ai score=98)
MaxSecureTrojan.Malware.1275986.susgen
FortinetW32/Banload.CBR!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Banload.QDS

How to remove Trojan.Downloader.ciWfau8uKSeG?

Trojan.Downloader.ciWfau8uKSeG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment