Ransom Trojan

About “Trojan-Ransom.Win32.Agent.azfs” infection

Malware Removal

The Trojan-Ransom.Win32.Agent.azfs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Agent.azfs virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r1—sn-4g5e6ne6.gvt1.com

How to determine Trojan-Ransom.Win32.Agent.azfs?


File Info:

crc32: F0D0A4A6
md5: 3e05cdc35f300de783fcb3dcd71e4970
name: 3E05CDC35F300DE783FCB3DCD71E4970.mlw
sha1: abfc51fe7bc93d12d0d163b1f7fecae0a6a8e52e
sha256: adc220109f73acdd307036a6d14bffa68103a48e2305c3a4f1533aab74d9deb8
sha512: fff156d64fcd720d2d27b3e53dccb9fb817775b11b04eae44e41bb266112f3655ced03ef3e6037748155bdd02b6d749eda778e92eb66a9362546513c48ce4775
ssdeep: 98304:ocHxAWpnC6vMjoGDn8d1LqiYErL63aTrmOjaL8SIOv9r:TiWpogdVg9l
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Microsoft Corporation.All rights reserved.
FileVersion: 10.0.18362.1
CompanyName: Microsoft Corp
Comments: Service Host, or SvcHost is a system process that can host from one to many Windows services in the Windows NT family of operating systems. Svchost is essential in the implementation of so-called shared service processes, where a number of services can share a process in order to reduce resource consumption. This program is important for the stable and secure running of your computer and should not be terminated.
ProductName: Microsoft Windows Operating System
ProductVersion: 10.0.18362.1
FileDescription: Microsoft Windows Operating System
Translation: 0x0804 0x04b0

Trojan-Ransom.Win32.Agent.azfs also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35873483
McAfeeArtemis!3E05CDC35F30
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.35873483
K7GWTrojan ( 0055bc761 )
K7AntiVirusTrojan ( 0055bc761 )
ArcabitTrojan.Generic.D22362CB
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Agent.azfs
AlibabaRansom:Win32/Themida.5fe16e20
AegisLabTrojan.Win32.Agent.j!c
Ad-AwareTrojan.GenericKD.35873483
EmsisoftTrojan.GenericKD.35873483 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.Packed.193
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.3e05cdc35f300de7
SophosMal/Generic-S
IkarusTrojan.Kasidet
MAXmalware (ai score=100)
KingsoftWin32.Troj.Generic.a.(kcloud)
GridinsoftTrojan.Win32.Packed.oa
MicrosoftTrojan:Win32/CryptInject!ml
ZoneAlarmTrojan-Ransom.Win32.Agent.azfs
GDataWin32.Trojan.Agent.P32KUK
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Filecoder
TACHYONRansom/W32.16x.4633408
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.MalPack.Themida
ESET-NOD32a variant of Win32/Packed.Themida.HFL
eGambitPE.Heur.InvalidSig
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34700.@x2@a4Slskab
AVGWin32:Trojan-gen
Cybereasonmalicious.e7bc93
Paloaltogeneric.ml
Qihoo-360Trojan.Generic

How to remove Trojan-Ransom.Win32.Agent.azfs?

Trojan-Ransom.Win32.Agent.azfs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment