Malware

Win32/Agent.UFD removal tips

Malware Removal

The Win32/Agent.UFD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.UFD virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Agent.UFD?


File Info:

name: CF646C5F74E68BDCC486.mlw
path: /opt/CAPEv2/storage/binaries/42b0a69574bd609d7f6bdbeae81782cfe0202e394bb1a75b255cb104b2d45f90
crc32: 7FE072D4
md5: cf646c5f74e68bdcc486638c3a712010
sha1: e9e7f2d3e68e269d82c7d830d74d826295ab9a5f
sha256: 42b0a69574bd609d7f6bdbeae81782cfe0202e394bb1a75b255cb104b2d45f90
sha512: bd929c6019e1760fdaaa9d76f6fdc44ecbb9d1c7c582a346e056944602fc99c52697394d00c6bd282942d32e9f43d0942db441d9730091c856cd1a5b73f14c4a
ssdeep: 49152:ABREW7vZ9fYBOPAko0qKLFm2+ie0/G9Zp6eeE06mGt6z:ab3fZAk09H10/UZoYmGtg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DAB52312B9C0D8F3D4621832166E4B02E97E7E312BA99DEFD7D06A5DA9311D0DB313B4
sha3_384: 33c473972303483abc4a01210f869463c3cab67b5dc36f6dbaf8f9deb261c860144c97de721a5a1da16217658868b22e
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Win32/Agent.UFD also known as:

BkavW32.AIDetect.malware1
FireEyeGeneric.mg.cf646c5f74e68bdc
CAT-QuickHealTrojan.Win32CiR
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004e47071 )
K7GWTrojan ( 005927fe1 )
CyrenW32/S-e021834d!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.UFD
APEXMalicious
ClamAVWin.Malware.Fugrafa-9938779-0
KasperskyTrojan.Win32.Agent.xapnpl
AvastWin32:Trojan-gen
SophosGeneric ML PUA (PUA)
ComodoMalware@#3ho7dxbd2shfl
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
IkarusTrojan.Win32.Agent
AviraTR/Agent.pjwag
ZoneAlarmTrojan.Win32.Agent.xapnpl
GDataWin32.Trojan.Agent.3SQQWB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R478670
Acronissuspicious
VBA32Trojan.Wacatac
RisingTrojan.Generic@AI.94 (RDML:VH8bvrPbReyXaqpKQ2rFDQ)
FortinetW32/Agent.UFD!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen

How to remove Win32/Agent.UFD?

Win32/Agent.UFD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment