Trojan

How to remove “TrojanDownloader:Win32/Kanav.F”?

Malware Removal

The TrojanDownloader:Win32/Kanav.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Kanav.F virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings

How to determine TrojanDownloader:Win32/Kanav.F?


File Info:

name: 11E0EA5EDCB21EEE1DE3.mlw
path: /opt/CAPEv2/storage/binaries/204c911056857e8e933eb5165e81060a3019e1b659f5a7efcc946d3a0e1b625f
crc32: F49AABCA
md5: 11e0ea5edcb21eee1de3c65bf6fd4626
sha1: 0bf2f6af4146e22eb6207250fdcf56ca4d77c0dc
sha256: 204c911056857e8e933eb5165e81060a3019e1b659f5a7efcc946d3a0e1b625f
sha512: d5b78c0f252fb4f3f6f4cc9362ca779ad9e4ef09a6571b1d8c60af024800192a263a216c20ecde161135d32a968e19655ac75757213eed3ca6af51a3578b425c
ssdeep: 3072:anBZfet8bR1TkkbXdiNbxXCDhDtjukOwK04mCmBKIQKcqcxQsyQ321Agq4i6b+ZO:ajDFl3ixxm7CmBKIQDqcxQrQmjJiA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C524AF627E90E232D8594271A1DD67725739BA3D27149EC3CB005B8B78B4ED1BE3834B
sha3_384: 6b91e6c1f2e722de82c2a84b2db149667d46b0099e3c433d6e31fca651178166533429ba841c23e0743b1059520a6596
ep_bytes: e98d19010083ed02f8ff3424c60424fa
timestamp: 2012-12-16 07:38:39

Version Info:

0: [No Data]

TrojanDownloader:Win32/Kanav.F also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Vobfus.lHUj
MicroWorld-eScanGen:Variant.Doina.19648
ClamAVWin.Trojan.Agent-522581
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXDK-KH!11E0EA5EDCB2
CylanceUnsafe
VIPREGen:Variant.Doina.19648
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0055e39b1 )
K7GWTrojan ( 0055e39b1 )
Cybereasonmalicious.edcb21
BaiduWin32.Trojan.Alyak.a
CyrenW32/Agent.QC.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Alyak.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.okzl
BitDefenderGen:Variant.Doina.19648
NANO-AntivirusTrojan.Win32.Drop.bgaqjv
AvastWin32:Agent-APWI [Trj]
TencentMalware.Win32.Gencirc.10b9ef76
Ad-AwareGen:Variant.Doina.19648
EmsisoftGen:Variant.Doina.19648 (B)
ComodoTrojWare.Win32.TrojanDownloader.Kanav.FA@4u2tvg
DrWebTrojan.MulDrop4.17168
ZillyaTrojan.Alyak.Win32.51
TrendMicroTROJ_GEN.R067C0DJ222
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.11e0ea5edcb21eee
SophosML/PE-A + Troj/Kanav-D
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Doina.19648
JiangminTrojan/Generic.aqvev
AviraHEUR/AGEN.1212012
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.24D
ArcabitTrojan.Doina.D4CC0
ViRobotTrojan.Win32.Downloader.210944.AC
MicrosoftTrojanDownloader:Win32/Kanav.F
GoogleDetected
AhnLab-V3Dropper/Win32.OnlineGameHack.R46355
VBA32suspected of Trojan.Downloader.gen
ALYacGen:Variant.Doina.19648
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallTROJ_GEN.R067C0DJ222
RisingDownloader.Kanav!8.341 (TFE:2:6M945YMMUZK)
IkarusTrojan-Downloader.Win32.Kanav
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Alyak.B!tr
BitDefenderThetaAI:Packer.F6E1F0671E
AVGWin32:Agent-APWI [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Kanav.F?

TrojanDownloader:Win32/Kanav.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment