Trojan

TrojanClicker:Win32/Olafre.A removal tips

Malware Removal

The TrojanClicker:Win32/Olafre.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanClicker:Win32/Olafre.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanClicker:Win32/Olafre.A?


File Info:

name: 9F9153D12366E192D85E.mlw
path: /opt/CAPEv2/storage/binaries/479e889a5f4eb257efd9d7e4feab3712a6fe2eb14295349f7b93de46048cbb0f
crc32: C11D4472
md5: 9f9153d12366e192d85e82d2ecd3a286
sha1: 0e480b7f028a63c8909ad8318ee5774fc96fa55c
sha256: 479e889a5f4eb257efd9d7e4feab3712a6fe2eb14295349f7b93de46048cbb0f
sha512: 516973cf13c7f3a61fa7ffe8fd1d10ca053d8089dd7a6b3aca545f227b3c75db6a73f5c989a90fe709cf95a84080bb537c5b9ad2496ba8151c2e22d85fd0a229
ssdeep: 12288:pLHULTl4x2z6DmGWT6U3ce/lR9YtDjdT:pTr2ODUhMJ/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19CA47E32B3E04437D1631E7CDD1B96AC982ABE903D289C863BE41D8D5F39781752B297
sha3_384: ddbafe2ee6633700ad8b1ee161f573e7e30bfafa23a27408206b9a5ab4cad754b6f98fc6d06edf358b88834149e947db
ep_bytes: 558bec83c4ec33c08945ecb860d74500
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanClicker:Win32/Olafre.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.TrojanClicker.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.143296
FireEyeGen:Variant.Midie.143296
CAT-QuickHealTrojan.DelfPMF.S32573232
SkyhighBehavesLike.Win32.ObfuscatedPoly.gh
ALYacGen:Variant.Midie.143296
Cylanceunsafe
SangforTrojan.Win32.Delf.Vh1a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanClicker:Win32/Olafre.faa7206f
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
BaiduWin32.Trojan.Delf.gb
VirITTrojan.Win32.Generic.JYH
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.YS
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT_001853.TOMB
ClamAVWin.Trojan.Delf-5198
KasperskyTrojan.Win32.Delf.ys
BitDefenderGen:Variant.Midie.143296
NANO-AntivirusTrojan.Win32.Delf.dxprhz
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:Delf-JAN [Trj]
TencentMalware.Win32.Gencirc.10b14a2a
EmsisoftGen:Variant.Midie.143296 (B)
F-SecureTrojan.TR/Crypt.CFI.Gen
DrWebTrojan.Siggen.52989
VIPREGen:Variant.Midie.143296
TrendMicroTROJ_AGENT_001853.TOMB
Trapminemalicious.high.ml.score
SophosMal/Bancos-A
JiangminTrojan/Delf.ake
GoogleDetected
AviraTR/Crypt.CFI.Gen
VaristW32/Delf.L.gen!Eldorado
Antiy-AVLTrojan/Win32.Delf
Kingsoftmalware.kb.a.999
MicrosoftTrojanClicker:Win32/Olafre.A
XcitiumTrojWare.Win32.TrojanClicker.Agent.~AZD@7j5bb
ArcabitTrojan.Midie.D22FC0
ViRobotTrojan.Win32.Delf.Gen.A
ZoneAlarmTrojan.Win32.Delf.ys
GDataGen:Variant.Midie.143296
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Delf.R1364
McAfeeGenDownloader.d
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesGeneric.Trojan.Delf.DDS
PandaAdware/Clicker
RisingTrojan.Clicker.Delf.ql (CLASSIC)
YandexTrojan.GenAsa!B2ps6gLR/Ps
IkarusTrojan-Dropper.Delf
MaxSecureTrojan.Malware.480537.susgen
FortinetW32/Delf.YS!tr
BitDefenderThetaAI:Packer.A48D435818
AVGWin32:Delf-JAN [Trj]
Cybereasonmalicious.12366e
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Delf.YS

How to remove TrojanClicker:Win32/Olafre.A?

TrojanClicker:Win32/Olafre.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment