Trojan

TrojanDropper:Win32/Fainli.A removal

Malware Removal

The TrojanDropper:Win32/Fainli.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Fainli.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDropper:Win32/Fainli.A?


File Info:

name: 1C51E24737BFD18B0570.mlw
path: /opt/CAPEv2/storage/binaries/19472354b2c57a6090f9520dc3b3f68aa802174096580e4731b510975948a9f8
crc32: 386955F2
md5: 1c51e24737bfd18b057084ab733dd23d
sha1: 0c364a13baa8387eb2c76e74709fa2ad6acc2021
sha256: 19472354b2c57a6090f9520dc3b3f68aa802174096580e4731b510975948a9f8
sha512: 38b6c53991ab1dfa71e87069e5ddba4f9ad03ef1677dbf6285048082dfaceadc09b0625d8f4fd2b79dc74c6be097692aab4d41f688b16e6f9acc374d15ff5aa9
ssdeep: 12288:G4dUqn+NXh0gd1EGTN7UW+7Zzp9kmk7x:G4dUjxhPuGTAZrpk7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15994D0C7268361DBE7BBAA35DE27D9FA0F9B160CA499701140E155068F612F14CCCBAF
sha3_384: d89a080e3dcd765e00ee70c76516df167b38787bfae41560c55dc6394e7565855aed0de5d2ba66caffb33992e7288725
ep_bytes: 558bec83c4ec6a0068a60100006a036a
timestamp: 2007-04-11 23:30:09

Version Info:

0: [No Data]

TrojanDropper:Win32/Fainli.A also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Katusha.x!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.TDss.18
SkyhighBehavesLike.Win32.Dropper.gh
McAfeeArtemis!1C51E24737BF
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.1124346
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Katusha.4f925611
Cybereasonmalicious.737bfd
ArcabitTrojan.TDss.18
BitDefenderThetaGen:NN.ZexaF.36802.zqW@aSj6nTtO
VirITPacked.Win32.Katusha.J
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DXV
APEXMalicious
TrendMicro-HouseCallTROJ_KRAP.SMFB
ClamAVWin.Trojan.Agent-309259
KasperskyPacked.Win32.Katusha.j
BitDefenderGen:Variant.TDss.18
NANO-AntivirusTrojan.Win32.Katusha.bhlpe
AvastWin32:MalOb-AT [Cryp]
TencentWin32.Packed.Katusha.Pjgl
EmsisoftGen:Variant.TDss.18 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
VIPREGen:Variant.TDss.18
TrendMicroTROJ_KRAP.SMFB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1c51e24737bfd18b
SophosMal/FakeAV-BT
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.hyq
WebrootW32.Downloader.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
VaristW32/FakeAlert.FY.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.a
XcitiumPacked.Win32.Katusha.~J@2rk6xi
MicrosoftTrojanDropper:Win32/Fainli.A
ZoneAlarmPacked.Win32.Katusha.j
GDataGen:Variant.TDss.18
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R96
ALYacGen:Variant.TDss.18
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Katusha.J
RisingTrojan.Generic@AI.93 (RDML:ldAdNFx08P5YUY7jpBckJA)
YandexTrojan.DR.Fainli!qobo+CRYv3c
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.891647.susgen
FortinetW32/Zbot.NT!tr
AVGWin32:MalOb-AT [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudVirtool:Win/Katusha.j

How to remove TrojanDropper:Win32/Fainli.A?

TrojanDropper:Win32/Fainli.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment