Trojan

Win32/TrojanDownloader.Agent.FAF information

Malware Removal

The Win32/TrojanDownloader.Agent.FAF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.FAF virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

wpad.local-net
crl.verisign.com
s1.symcb.com

How to determine Win32/TrojanDownloader.Agent.FAF?


File Info:

name: CF8E915A57235367F06D.mlw
path: /opt/CAPEv2/storage/binaries/e9d23f584f8d60976ef13c2ee33efca83f09bdf03ed7b9a38355f2a1fb8a6edc
crc32: 740FF634
md5: cf8e915a57235367f06df592f2f9a39f
sha1: 00025a1bd19752aa9f5d6ecd918c08fc4615d14d
sha256: e9d23f584f8d60976ef13c2ee33efca83f09bdf03ed7b9a38355f2a1fb8a6edc
sha512: 37333a079e78076100d1656a3adc8e811aea6d4de21dcca25fb1d1b77003cd1f6483a8d6151d6b324055ccd551189267143f497294efefbbd7fd29e7e1b8ff30
ssdeep: 196608:HH3cUtv1lCYpcGVElSd9fG3FzxQGoNRhAVfwoT:35tv1wLG7fG1aGo/hQfj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1716633850A6DD390F40FE374010D6783A69B6C5C52D6095DCEB2B319E8FA3C3BB3A599
sha3_384: bce3f1e6f6f2186b75ac50a840b02e0f5bb8a61c4df42de1bc860b9d127f488b98307bf41c3645c28df08e9c5277245c
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:52:01

Version Info:

Comments:
CompanyName: $CmpName
FileDescription: 极速开票
FileVersion: 4.0.0.4
InternalName: $Name
LegalCopyright: 版权所有 (C) 诺诺网
LegalTrademarks: 诺诺网
OriginalFilename:
PrivateBuild:
ProductName: 极速开票 4.0.0.4
ProductVersion: $Ver
SpecialBuild:
Translation: 0x0000 0x03a8

Win32/TrojanDownloader.Agent.FAF also known as:

Elasticmalicious (high confidence)
McAfeeArtemis!CF8E915A5723
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FAF
APEXMalicious
AvastFileRepMetagen [PUP]
TencentWin32.Trojan-downloader.Agent.Tcck
ComodoMalware@#19f2uska6am10
ZillyaTrojan.Reconyc.Win32.21064
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
IkarusTrojan-Downloader.Win32.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32Trojan.Reconyc
MalwarebytesAdware.Agent
AVGFileRepMetagen [PUP]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/TrojanDownloader.Agent.FAF?

Win32/TrojanDownloader.Agent.FAF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment