Trojan

Win32/TrojanDownloader.Agent.CWI malicious file

Malware Removal

The Win32/TrojanDownloader.Agent.CWI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.CWI virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.Agent.CWI?


File Info:

name: 0AF953985D5AAECB516F.mlw
path: /opt/CAPEv2/storage/binaries/a72a5d5dde7c1af270fc131b67a9b7007e39aebd97baa72b15ce812b7a283816
crc32: 5615D518
md5: 0af953985d5aaecb516feb8391438412
sha1: b886b06f31f604fb6bc0b44542d3b0a72fc7bdc2
sha256: a72a5d5dde7c1af270fc131b67a9b7007e39aebd97baa72b15ce812b7a283816
sha512: ef21bbc36fa196c1b43ea7ac19a87f8fbbfa1776197f40be5486d1d8bc5ee69547d643c1989ba242138176c881516a9b4fb4802f77c7d20b48c6586ec56cfadd
ssdeep: 3072:q7lWcSzoFrJltLwmZGNcx+rAdvUXu3ER4+UUMVgwUUt2M4uxewcDVE9jEXb4+gT1:kOKtUEx6ovUXu3ER4+UUMVgwUUt2M4uL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AE37D167682C4DAC76340F1828B6B5F4F567E210E6270E757C47F0EAEF50B56A3B086
sha3_384: 3c2ff7827d71ad2cc695c5b0308e0e342220200d5efca32e2694ee742ea7fcb29257d23169f8df10aac3c1dfea5245ba
ep_bytes: 558bec6aff68b890400068506c400064
timestamp: 2014-09-14 07:20:22

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.CWI also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.25190
FireEyeGeneric.mg.0af953985d5aaecb
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXAN-DG!0AF953985D5A
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 005412be1 )
AlibabaTrojanDownloader:Win32/DropperX.3f32d43e
K7GWTrojan-Downloader ( 005412be1 )
Cybereasonmalicious.85d5aa
CyrenW32/Agent.DQN.gen!Eldorado
SymantecDownloader
ESET-NOD32Win32/TrojanDownloader.Agent.CWI
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Broskod-6804161-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Doina.25190
NANO-AntivirusTrojan.Win32.Dwn.dwrwuh
TencentMalware.Win32.Gencirc.10b0f069
Ad-AwareGen:Variant.Doina.25190
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Broskod.SA@6vorj1
DrWebTrojan.DownLoader16.16954
ZillyaBackdoor.Finfish.Win32.18
TrendMicroTROJ_GEN.R002C0OKR21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Doina.25190 (B)
Paloaltogeneric.ml
GDataWin32.Trojan.PSE.13RMOHK
JiangminBackdoor/Finfish.d
AviraHEUR/AGEN.1121102
Antiy-AVLTrojan/Generic.ASMalwS.E5F25C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Broskod.R190001
BitDefenderThetaGen:NN.ZexaF.34294.iqZ@aSTT2bcb
ALYacGen:Variant.Doina.25190
MAXmalware (ai score=87)
VBA32Trojan.Broskod
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R002C0OKR21
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CWI!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/TrojanDownloader.Agent.CWI?

Win32/TrojanDownloader.Agent.CWI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment