Trojan

Trojan.Downloader.mmKfa8CB!ioO removal tips

Malware Removal

The Trojan.Downloader.mmKfa8CB!ioO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.mmKfa8CB!ioO virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Downloader.mmKfa8CB!ioO?


File Info:

name: 5743ED7FAC4ABF092004.mlw
path: /opt/CAPEv2/storage/binaries/065a920fb7adaaab4d149589b65a0f97954f0c7f68eca2c297735a73deb6dfdf
crc32: 5769D9D5
md5: 5743ed7fac4abf092004958dd13cf4e1
sha1: cf8912211038f495032c2fb4f86102118557c002
sha256: 065a920fb7adaaab4d149589b65a0f97954f0c7f68eca2c297735a73deb6dfdf
sha512: 3dfb80b5c3e6fbc3f50535590f26b7bc2c765d7ace500e57835e062e61ebeffb6fb5adcd3c554d1af8e6660635cbb401c23a23745c70aae461ce547a0f78f9fc
ssdeep: 6144:UvX1tlTZYZeS6ZIbtpxh56+7o6YwE4GK:qtlTCZeSIIbtL6+7k4G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4241320EB85C103EB72BC705FAA1DF8AF71F944469627613EB8440A5F7D6E9CBC1518
sha3_384: d12b94084d88ad0651fbaf717cb7b2395ce2f045dd9ca434b75abbbb3697b0a1d6f8297ea34369fc3e4201600cca9109
ep_bytes: 60be00a045008dbe0070faffc787a0e0
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription: 실행파일
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0412 0x03b5

Trojan.Downloader.mmKfa8CB!ioO also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.l4zT
MicroWorld-eScanGen:Trojan.Downloader.mmKfa8CB!ioO
SkyhighBehavesLike.Win32.ObfuscatedPoly.dc
ALYacGen:Trojan.Downloader.mmKfa8CB!ioO
MalwarebytesDelphi.Trojan.Downloader.DDS
VIPREGen:Trojan.Downloader.mmKfa8CB!ioO
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Trojan.Downloader.mmKfa8CB!ioO
K7GWTrojan ( 7000000f1 )
VirITTrojan.Win32.Generic.CIVY
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.QJQ
APEXMalicious
ClamAVWin.Trojan.Genome-9328
KasperskyTrojan-Downloader.Win32.Genome.coos
AlibabaTrojanDownloader:Win32/Genome.e81697da
NANO-AntivirusTrojan.Win32.DownLoad2.bxpeux
ViRobotTrojan.Win.Z.Genome.209408
RisingDownloader.Delf!8.16F (CLOUD)
SophosMal/Generic-S
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebTrojan.DownLoad2.19268
ZillyaDownloader.Genome.Win32.40619
TrendMicroTSPY_DOWNLOADER_CD102E01.RDXN
FireEyeGen:Trojan.Downloader.mmKfa8CB!ioO
EmsisoftGen:Trojan.Downloader.mmKfa8CB!ioO (B)
IkarusTrojan.Win32.Agent
MAXmalware (ai score=100)
JiangminTrojanDownloader.Genome.sgd
WebrootW32.Downloader.Gen
GoogleDetected
AviraTR/ATRAPS.Gen2
VaristW32/Downloader.EE.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Genome
MicrosoftTrojan:Win32/Bumat!rts
XcitiumMalware@#29ezktpk0l8a7
ArcabitTrojan.Downloader.mmKfa8CB!ioO
ZoneAlarmTrojan-Downloader.Win32.Genome.coos
GDataGen:Trojan.Downloader.mmKfa8CB!ioO
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Overtls.R2372
McAfeeArtemis!5743ED7FAC4A
DeepInstinctMALICIOUS
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_DOWNLOADER_CD102E01.RDXN
TencentWin32.Trojan-Downloader.Genome.Qzfl
YandexTrojan.GenAsa!QbXwCO07Tms
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.3457764.susgen
FortinetW32/Delf.BHO!tr.dldr
BitDefenderThetaGen:NN.ZelphiF.36792.mmKfa8CB!ioO
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Downloader.mmKfa8CB!ioO?

Trojan.Downloader.mmKfa8CB!ioO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment