Trojan

TrojanDownloader:Win32/Caftuli.A information

Malware Removal

The TrojanDownloader:Win32/Caftuli.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Caftuli.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Caftuli.A?


File Info:

name: 64E40B1A4DFEDB569F22.mlw
path: /opt/CAPEv2/storage/binaries/23f6f96341ebb5464ce973e7241704e8736932c01ab3e718e5e94aff8739e49d
crc32: 38EB108C
md5: 64e40b1a4dfedb569f2289bad7f0ebe2
sha1: 478b98c9a20764dc6ed1d3bb12471eb703cba96d
sha256: 23f6f96341ebb5464ce973e7241704e8736932c01ab3e718e5e94aff8739e49d
sha512: 04d0608b34df438aa8266469f848abf468506db6ad49a306dd0dcbed8518592a92febef16b3e01875f8a700724a5cb2c77ecfd6fdd2c86bec4cb307fb218b324
ssdeep: 3072:wGs5Hdoa1XYwvV2LBMZtYDJgTkKa1+Ev1+E:RMWhwMBMfYZIN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131A4A0B67099D5D7C103C572F872A9F71EA2EC17C83E86636D867E8936722B17003E19
sha3_384: 69b54a5399e1a865fdbdda3197c2f4dbcc165cd8f1209601eee94fc8b58d95c58fcb2bb1f4d760ad56227e81bb10d6ca
ep_bytes: 6804304200e8eeffffff000000000000
timestamp: 2011-09-01 05:56:55

Version Info:

Translation: 0x0412 0x04b0
CompanyName: home
ProductName: 다운로드
FileVersion: 1.00
ProductVersion: 1.00
InternalName: powerutil
OriginalFilename: powerutil.exe

TrojanDownloader:Win32/Caftuli.A also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Generic.KDV.365086
FireEyeGeneric.mg.64e40b1a4dfedb56
SkyhighBehavesLike.Win32.VBObfus.gm
McAfeeGenericRXFZ-QA!64E40B1A4DFE
Cylanceunsafe
ZillyaTrojan.VB.Win32.165169
SangforTrojan.Win32.Agent.atgen
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanDownloader:Win32/Caftuli.2599af08
K7GWP2PWorm ( 0055e3ea1 )
K7AntiVirusP2PWorm ( 0055e3ea1 )
ArcabitTrojan.Generic.KDV.D5921E
BitDefenderThetaGen:NN.ZevbaF.36680.Cm0@aa28t@jO
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/VB.PZL
CynetMalicious (score: 99)
BitDefenderTrojan.Generic.KDV.365086
NANO-AntivirusTrojan.Win32.Gendal.nrawk
AvastWin32:Trojan-gen
TencentWin32.Trojan.Agen.Ftgl
F-SecureHeuristic.HEUR/AGEN.1336445
VIPRETrojan.Generic.KDV.365086
EmsisoftTrojan.Generic.KDV.365086 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.gen
GoogleDetected
AviraHEUR/AGEN.1336445
Antiy-AVLTrojan[Downloader]/Win32.VB
KingsoftWin32.Troj.Unknown.a
XcitiumMalware@#2kqw1ielc75ry
MicrosoftTrojanDownloader:Win32/Caftuli.A
GDataTrojan.Generic.KDV.365086
VaristW32/VB.GN.gen!Eldorado
VBA32suspected of Trojan.Downloader.gen
ALYacTrojan.Generic.KDV.365086
MAXmalware (ai score=83)
MalwarebytesMalware.AI.4247637603
PandaTrj/CI.A
RisingDownloader.Caftuli!8.7B69 (TFE:5:k6v5fHmOIqE)
YandexTrojan.VB!gaHs7qJ1em8
IkarusTrojan.VB
MaxSecureTrojan.Malware.2309258.susgen
FortinetW32/Agent.PZL!tr.dldr
AVGWin32:Trojan-gen
Cybereasonmalicious.9a2076
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Caftuli.A?

TrojanDownloader:Win32/Caftuli.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment