Trojan

About “Trojan.GenericFCA.Agent.44605” infection

Malware Removal

The Trojan.GenericFCA.Agent.44605 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericFCA.Agent.44605 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.GenericFCA.Agent.44605?


File Info:

name: C21C2985B084FBBB4A35.mlw
path: /opt/CAPEv2/storage/binaries/3c56a50e5eb86ef1b519204bc622d473dc73c00594baf657bc52bb42fd2af631
crc32: F191BB32
md5: c21c2985b084fbbb4a35d4911323ac23
sha1: 50d0f755b47f3eb7cc7766fd80f5b3666e2c6fe9
sha256: 3c56a50e5eb86ef1b519204bc622d473dc73c00594baf657bc52bb42fd2af631
sha512: b8a5fa271cc558f1e0443acd7388c93c6d42ae13769426b50feff7f7efdf2d650e6e465cb8b20570f45b64e639f50bef04035e895e7d6526a41c84a0e370f299
ssdeep: 49152:9WN26FOnzGn6LJvqkwnpC+mWd6uIcchnYnnV7lSLq2gdPxTdKO8GPX:9W06FOznLo0+Dd6uxcJYnnVcu2gxxdKk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2D52342F782C0B1E8A504F94525D6B68E357D3247B6C4E37BD03A7E9E703D0EA3664A
sha3_384: 630d58a0e58a3390679d5661868e2404840e502af51d27b1d7aed233b18777550ed393befe6405dbee084a69b847bbf5
ep_bytes: e8a61d0000e989feffff8bff565733f6
timestamp: 2012-06-14 16:16:10

Version Info:

Comments: Created with Setup Factory
FileDescription: Setup Application
FileVersion: 9.1.0.0
InternalName: suf_launch
LegalCopyright: Setup Engine Copyright © 2004-2012 Indigo Rose Corporation
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
OriginalFilename: suf_launch.exe
ProductName: Setup Factory Runtime
ProductVersion: 9.1.0.0
Translation: 0x0409 0x04e4

Trojan.GenericFCA.Agent.44605 also known as:

LionicTrojan.Win32.Lotok.m!c
MicroWorld-eScanTrojan.GenericFCA.Agent.44605
ALYacTrojan.GenericFCA.Agent.44605
VIPRETrojan.GenericFCA.Agent.44605
K7AntiVirusTrojan ( 005963051 )
AlibabaBackdoor:Win32/Lotok.13c63167
K7GWTrojan ( 005963051 )
Cybereasonmalicious.5b47f3
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Dropper.Detected-9958947-0
KasperskyBackdoor.Win32.Lotok.ifv
BitDefenderTrojan.GenericFCA.Agent.44605
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Lotok.Sunk
Ad-AwareTrojan.GenericFCA.Agent.44605
EmsisoftTrojan.GenericFCA.Agent.44605 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
FireEyeTrojan.GenericFCA.Agent.44605
SophosMal/Generic-S
GDataTrojan.GenericFCA.Agent.44605
WebrootW32.Trojan.Gen
KingsoftWin32.Hack.Undef.(kcloud)
ArcabitTrojan.GenericFCA.Agent.DAE3D
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!C21C2985B084
MAXmalware (ai score=85)
RisingBackdoor.Lotok!8.111D5 (CLOUD)
IkarusTrojan.PowerShell.Disabler
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
PandaTrj/Chgt.AA

How to remove Trojan.GenericFCA.Agent.44605?

Trojan.GenericFCA.Agent.44605 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment