Trojan

Trojan.Dropper.SFXAI removal tips

Malware Removal

The Trojan.Dropper.SFXAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper.SFXAI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Interacts with known DarkComet registry keys
  • The sample wrote data to the system hosts file.
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Dropper.SFXAI?


File Info:

crc32: 36AE6932
md5: 7c995e3520c50bd7102abc6eb2caf3a7
name: 7C995E3520C50BD7102ABC6EB2CAF3A7.mlw
sha1: a14febc6a392f3e7b528a8673baa5d2d155f1e05
sha256: 61469cd1428330861a70c9e6421f2e590bf93f235cb65416073c3abd8b75389b
sha512: cba55b87257b55662a8a43aa0b26fa790a37d0471d8ecfc34d5b04c3dd5868f5e60bc2d40de7dee870d72097b039b38096fa1ec6a488df9f0b72106fa1bcbc8c
ssdeep: 24576:caUxvxK4jY1G970h5iN+Z5H5w+8YCWFqupsbsiBhzCHlrl+rH6GGXT9aC4tdNZHs:wJKGIhrZpG+8YLygiB45l+rgj9IdNFLA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Dropper.SFXAI also known as:

MicroWorld-eScanTrojan.Generic.13018638
FireEyeTrojan.Generic.13018638
CAT-QuickHealTrojanDropper.Slipafext
Qihoo-360Win32/Backdoor.PoisonIvy.HwYD4t8A
ALYacTrojan.Generic.13018638
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Generic.13018638
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.520c50
BitDefenderThetaAI:Packer.86E61DA51F
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R002C0DAQ21
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Poison.jpxq
AlibabaBackdoor:Win32/Poison.68fba014
NANO-AntivirusTrojan.Win32.Poison.iiwzid
ViRobotTrojan.Win32.Z.Dropper.1316962
Ad-AwareTrojan.Generic.13018638
SophosMal/Generic-S
ComodoApplication.Win32.BlkIC.IMG@1qp8gx
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_GEN.R002C0DAQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.Generic.13018638 (B)
IkarusTrojan.Dropper
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MicrosoftTrojanDropper:Win32/Slipafext.A
ArcabitTrojan.Generic.DC6A60E
ZoneAlarmBackdoor.Win32.Poison.jpxq
GDataTrojan.Generic.13018638
CynetMalicious (score: 90)
McAfeeGenericR-DDC!7C995E3520C5
MAXmalware (ai score=81)
MalwarebytesTrojan.Dropper.SFXAI
PandaTrj/CI.A
APEXMalicious
ESET-NOD32Win32/Fynloski.AA
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
YandexTrojan.Agent!wTU3m7o9E04
SentinelOneStatic AI – Suspicious PE
FortinetW32/GenericR.DDC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Dropper.SFXAI?

Trojan.Dropper.SFXAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment