Trojan

Trojan.FileInfector.amGfa0A48Fd removal instruction

Malware Removal

The Trojan.FileInfector.amGfa0A48Fd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FileInfector.amGfa0A48Fd virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.FileInfector.amGfa0A48Fd?


File Info:

name: 0E6424F621A2873BDB6A.mlw
path: /opt/CAPEv2/storage/binaries/c079fc4dd15429fd393fe4c345956dc102243cebc9c503a6998c9046977182f8
crc32: F13FDC29
md5: 0e6424f621a2873bdb6a91d836711089
sha1: ba0b4110957667dc6e84b1c53bf9b1763f8333a8
sha256: c079fc4dd15429fd393fe4c345956dc102243cebc9c503a6998c9046977182f8
sha512: 30d6be9a237ba822735de94b50f6a6fa7b538b404afc9b0ac87879ee7386cf136f6764c95ae33e488e01269d66ee2302e39239f0a7d177796cefcefb8cb0b7a8
ssdeep: 12288:hqV14uvb7CZGH3qFSpxt53E1pshT2hgBqV14uvb7CZGH3qFSpxt53E1pshT2hg8+:01rjdEbOU1rjdEbON1rjdEbO
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1C225B650A9805966DCB736FD4EEEB129762CFAC0130217C356E869FBDB127D13EB014A
sha3_384: 0835e21c9e36072127bf8b63bf2303b11370913a186584f1ccbe74ba851ffd5fc6391cc6cd50e3eac3b4abf918e76875
ep_bytes: 8bff558bec837d0c017505e8a7070000
timestamp: 2008-07-31 13:16:15

Version Info:

CompanyName: Microsoft Corporation
FileDescription: XACT Engine API
FileVersion: 9.24 (DXSDK_AUG08.080731-0600)
InternalName: XactEngine3_2.dll
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename: XactEngine3_2.dll
ProductName: Microsoft® DirectX for Windows®
ProductVersion: 9.24.1400.0
Translation: 0x0409 0x04b0

Trojan.FileInfector.amGfa0A48Fd also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.FileInfector.amGfa0A48Fd
ClamAVWin.Malware.Fileinfector-9834127-0
FireEyeGeneric.mg.0e6424f621a2873b
SkyhighArtemis!Trojan
McAfeeArtemis!0E6424F621A2
VIPREGen:Trojan.FileInfector.amGfa0A48Fd
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/CryptInject.091b7379
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Trojan.FileInfector.amGfa0A48Fd
NANO-AntivirusTrojan.Win32.Clicker.dapdse
AvastWin32:TrojanX-gen [Trj]
SophosTroj/Agent-BGLN
F-SecureTrojan.TR/Patched.dfzj
DrWebTrojan.Click3.29339
EmsisoftGen:Trojan.FileInfector.amGfa0A48Fd (B)
IkarusTrojan.Win32.Ymacco
GDataGen:Trojan.FileInfector.amGfa0A48Fd
GoogleDetected
AviraTR/Patched.dfzj
Antiy-AVLTrojan/Win32.Agent.cgr
ArcabitTrojan.FileInfector.amGfa0A48Fd
MicrosoftTrojan:Win32/Vindor!pz
VaristW32/Agent.CGR.gen!Eldorado
AhnLab-V3Trojan/Win.CryptInject.C4594737
BitDefenderThetaGen:NN.ZexaF.36680.amGfa0A48Fd
ALYacGen:Trojan.FileInfector.amGfa0A48Fd
MAXmalware (ai score=82)
VBA32Trojan.Click
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.CGR!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.FileInfector.amGfa0A48Fd?

Trojan.FileInfector.amGfa0A48Fd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment