Trojan

Trojan:Win32/Fuery.ASN!MTB (file analysis)

Malware Removal

The Trojan:Win32/Fuery.ASN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Fuery.ASN!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Fuery.ASN!MTB?


File Info:

name: 8BC4D166AF4E1C30A029.mlw
path: /opt/CAPEv2/storage/binaries/a9e71455cfaa1a38e2836006aa315d669b273aa571093852fb9981cbbf27e17d
crc32: 4B1C40D5
md5: 8bc4d166af4e1c30a02989bfddfa7639
sha1: b26ade698402c058e61ef0a902b919e797cbf937
sha256: a9e71455cfaa1a38e2836006aa315d669b273aa571093852fb9981cbbf27e17d
sha512: 647fa94f56c0f68a0dfc234047cb9aedb2db4697cd8df08d6e699c61a5ed4cdca20834a06bc46452543c2507b98126f550517d5044826486a495bb1615415846
ssdeep: 24576:AcoXvzOopJvUCJ2wnyqii8Y39Wr17jEDICX0MLmJMPX6uPcHa1vhyV:hoXvzPpVrJ2wnyqii8YNWZEDICX0MLmB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F155D05A1A9348A1FE45C2348B9FD3B344560C727EAD1C7B685A7B31E1389F2C53F18A
sha3_384: b8c6c9eb504f10a8f0e7163b74ac4a0e52b76739b67b0af6308033dad1e7d979a30ae7ae4853eb7d65c1adc9752d161e
ep_bytes: e839600000e979feffffcccccccccccc
timestamp: 2014-03-11 10:54:23

Version Info:

CompanyName: Tencent
FileDescription: TASLogin Application
FileVersion: 2, 0, 27, 13735
InternalName: TASLogin
LegalCopyright: Copyright (C) 2012
ProductName: TASLogin Application
ProductVersion: 2, 0, 27, 13735
SpecialBuild: st
Comments: 2014-03-10
Translation: 0x0804 0x04b0

Trojan:Win32/Fuery.ASN!MTB also known as:

BkavW32.Common.EE5E5105
LionicTrojan.Win32.ShellCode.3!c
tehtrisGeneric.Malware
DrWebWin32.HLLP.Siggen.54
MicroWorld-eScanTrojan.GenericKDZ.98311
ClamAVWin.Trojan.Generic-9864088-0
SkyhighBehavesLike.Win32.Generic.tc
ALYacTrojan.GenericKDZ.98311
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.98311
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0015dce31 )
AlibabaVirus:Win32/Obfuscated.1062
K7GWTrojan ( 0015dce31 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D18007
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.IW
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Exploit.Win32.ShellCode.gen
BitDefenderTrojan.GenericKDZ.98311
TencentTrojan.Win32.Bingoml.yb
SophosTroj/Patched-BS
F-SecureTrojan.TR/Patched.Ren.Gen
ZillyaTrojan.GenericKD.Win32.43907
TrendMicroTROJ_GEN.R002C0DKG23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8bc4d166af4e1c30
EmsisoftTrojan.GenericKDZ.98311 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=86)
Antiy-AVLGrayWare/Win32.Patched.bak
Kingsoftmalware.kb.a.863
XcitiumHeur.Corrupt.PE@1z141z3
MicrosoftTrojan:Win32/Fuery.ASN!MTB
ZoneAlarmHEUR:Exploit.Win32.ShellCode.gen
GDataTrojan.GenericKDZ.98311
VaristW32/Patched.FI.gen!Eldorado
McAfeePacked-FAQ!8BC4D166AF4E
VBA32BScope.Trojan.Fuery
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DKG23
RisingTrojan.Patch!1.B0CA (CLASSIC)
YandexTrojan.GenAsa!D2ejYSL96j4
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IW!tr
Cybereasonmalicious.98402c
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Fuery.ASN!MTB?

Trojan:Win32/Fuery.ASN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment