Trojan

About “Trojan:Win32/Cefyns!A” infection

Malware Removal

The Trojan:Win32/Cefyns!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cefyns!A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Cefyns!A?


File Info:

name: 6477C8545DBEE360E227.mlw
path: /opt/CAPEv2/storage/binaries/bca50f3763975b6a7dde180f16ce54613de51d12a6a0b32435983b39db528ed7
crc32: B409F941
md5: 6477c8545dbee360e227caff7b80c38e
sha1: caa50d0c9e125e533e1b70d74c9ecd53bc51fc8e
sha256: bca50f3763975b6a7dde180f16ce54613de51d12a6a0b32435983b39db528ed7
sha512: 8c9ac16909b25132e2419fcd683ee81da9b7e6ad0cb4aa17a8745be817fa59a55b0ec26574240a114480bacf410ea3a78f079a19a30d174d9522dafbe2a960f5
ssdeep: 1536:2uf+8/PGnWYJJuVbK8+trXY+LxishYzaDiUQExbO+y:7GnWkDX3tYzaDpQwbLy
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T14263F191FB85DA05CC7615B90CAF86C02E6BEC214F18DF0BB29C7ACF2B7C2446651352
sha3_384: 6dbd8c439fdbdc3249f68638652780780d2a274c17dcfa29b87e4b6d61109ad0105c8927d7ca53cda793aa61eb2d05ef
ep_bytes: 807c2408010f85c201000060be008001
timestamp: 2008-05-04 16:10:23

Version Info:

CompanyName:
FileDescription: MsCmp1 Module
FileVersion: 1, 0, 0, 1
InternalName: MsCmp1
LegalCopyright: Copyright 2005
OriginalFilename: MsCmp1.DLL
ProductName: MsCmp1 Module
ProductVersion: 1, 0, 0, 1
OLESelfRegister:
Translation: 0x0409 0x04b0

Trojan:Win32/Cefyns!A also known as:

LionicTrojan.Win32.Vapsup.4!c
DrWebTrojan.DownLoad.6921
MicroWorld-eScanTrojan.Generic.708521
FireEyeGeneric.mg.6477c8545dbee360
SkyhighBehavesLike.Win32.Dropper.kc
McAfeeArtemis!6477C8545DBE
Cylanceunsafe
ZillyaTrojan.Vapsup.Win32.904
SangforAdware.Win32.AdSpy.Gen2
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Vapsup.8cc3d66d
BitDefenderThetaGen:NN.ZedlaF.36744.emSfaaD5zyki
VirITTrojan.Win32.Agent_r.B
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Adware.BHO.NJU
ClamAVWin.Trojan.Zlob-7452
KasperskyTrojan.Win32.Vapsup.mpdd
BitDefenderTrojan.Generic.708521
NANO-AntivirusTrojan.Win32.Vapsup.cwmwuw
AvastWin32:Vapsup-HE [Trj]
TencentWin32.Risk.ADSPY.Psmw
EmsisoftTrojan.Generic.708521 (B)
GoogleDetected
F-SecureAdware.ADSPY/AdSpy.Gen2
VIPRETrojan.Generic.708521
TrendMicroTROJ_FRS.0NA103B724
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.708521
JiangminTrojan/Vapsup.jrl
WebrootW32.Malware.Gen
VaristW32/Trojan.XRFW-6354
AviraADSPY/AdSpy.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Vapsup
KingsoftWin32.Trojan.Convagent.gen
XcitiumMalware@#29r3222yin9fd
ArcabitTrojan.Generic.DACFA9
ViRobotTrojan.Win32.A.Vapsup.69120.C[UPX]
ZoneAlarmTrojan.Win32.Vapsup.mpdd
MicrosoftTrojan:Win32/Cefyns.gen!A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vapsup.C21330
ALYacTrojan.Generic.708521
VBA32BScope.Trojan.Download
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B724
RisingMalware.Undefined!8.C (TFE:5:0AD0cGmfGCS)
YandexTrojan.GenAsa!xplywObDF2Y
IkarusTrojan.Zlob
MaxSecureTrojan.Malware.1728101.susgen
FortinetAdware/Vapsup
AVGWin32:Vapsup-HE [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Cefyns!A?

Trojan:Win32/Cefyns!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment