Trojan

What is “Trojan.Win32.Agent.ifuw”?

Malware Removal

The Trojan.Win32.Agent.ifuw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.ifuw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Trojan.Win32.Agent.ifuw?


File Info:

name: EC1C929AA8F204D23B35.mlw
path: /opt/CAPEv2/storage/binaries/0d9aee7c02249330c3d123f71333a0474ab63c0d068c8ef6724ad65459a5d72c
crc32: B8249BC9
md5: ec1c929aa8f204d23b3542e4dd76ed00
sha1: 1a0568cb143cee04ec67128bffe5300f7c708d9c
sha256: 0d9aee7c02249330c3d123f71333a0474ab63c0d068c8ef6724ad65459a5d72c
sha512: 9c001afaeddbbdd73e0caaa6a912f2b9608627d8c5293626ab0a35ed92fff0a24aae7ae8c9b6152dc2fe1421d15e037b81275873661a0547c8064528984d2abb
ssdeep: 1536:eUHuEvVIBphmpVbgtIcRXa8eVQBcgxv8S:eUHuEvopUZ6RiQBcgxkS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E963C0C7AA604073D550D378187ADBB475F2E8B5AF4392873A99CF4DA6B2F880823109
sha3_384: fd232ea2568f96d18c84b84447d381dc3db88d5b54c6ea6ba8ceb134e375c43afbb84806a835f28e8d21bc545d01f59a
ep_bytes: 558bec6aff68d026400068a21d400064
timestamp: 2015-07-07 18:27:33

Version Info:

0: [No Data]

Trojan.Win32.Agent.ifuw also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.1375
MicroWorld-eScanGen:Heur.Zboter.4
FireEyeGeneric.mg.ec1c929aa8f204d2
CAT-QuickHealTrojanPWS.Zbot.A4
McAfeePacked-FB!EC1C929AA8F2
MalwarebytesMalware.AI.798183777
ZillyaTrojan.Agent.Win32.559844
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004c7e1e1 )
AlibabaTrojan:Win32/DllCheck.6ccf2c23
K7GWTrojan ( 004c7e1e1 )
Cybereasonmalicious.aa8f20
BitDefenderThetaGen:NN.ZexaF.34212.eqZ@aG7ALVo
VirITTrojan.Win32.Inject2.CNOA
CyrenW32/S-1bc9580e!Eldorado
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Injector.CFGO
APEXMalicious
AvastSf:Agent-BA [Trj]
ClamAVWin.Malware.Blkx-6951312-0
KasperskyTrojan.Win32.Agent.ifuw
BitDefenderGen:Heur.Zboter.4
NANO-AntivirusTrojan.Win32.Encoder.dufbcp
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
TencentMalware.Win32.Gencirc.10b40bf9
Ad-AwareGen:Heur.Zboter.4
TACHYONTrojan/W32.Agent.70330.G
EmsisoftGen:Heur.Zboter.4 (B)
ComodoTrojWare.Win32.VirTool.CeeInject.KGR@5t0fp3
VIPRETrojan.Win32.Injector.cdgy (v)
TrendMicroBKDR_KELIHOS.SMNA
McAfee-GW-EditionPacked-FB!EC1C929AA8F2
SophosMal/Generic-R + Mal/Zbot-UE
Paloaltogeneric.ml
GDataGen:Heur.Zboter.4
JiangminTrojan/Agent.ijuv
WebrootW32.Trojan.Gen
AviraTR/Inject.sbbeinx
Antiy-AVLTrojan/Generic.ASBOL.2545
ZoneAlarmTrojan.Win32.Agent.ifuw
MicrosoftTrojan:Win32/DllCheck.A!MSR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CTBLocker.R158760
Acronissuspicious
VBA32OScope.Malware-Cryptor.Hlux
ALYacGen:Heur.Zboter.4
MAXmalware (ai score=100)
TrendMicro-HouseCallBKDR_KELIHOS.SMNA
RisingTrojan.Senta!8.66F (CLOUD)
YandexTrojan.Agent!iG93S2jwVks
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.CFFW!tr
AVGSf:Agent-BA [Trj]
PandaTrj/Zbot.R
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Agent.ifuw?

Trojan.Win32.Agent.ifuw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment