Trojan

What is “Win32/TrojanDownloader.Agent.FIL”?

Malware Removal

The Win32/TrojanDownloader.Agent.FIL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.FIL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

Related domains:

bitbucket.org

How to determine Win32/TrojanDownloader.Agent.FIL?


File Info:

crc32: 0D8146B4
md5: 9ed9f7afabfb805380dbcb5e96f2e0e4
name: 9ED9F7AFABFB805380DBCB5E96F2E0E4.mlw
sha1: 97f9ed4054e47f32e1ef538e21b4ce4969a15066
sha256: 91a63868ca56bae97b954c0ece75ed4f66e18bf2c258a9ed5712e376bae7220c
sha512: 6708fe40c276cae8d70b4eb1bf27766f1b3439ebcd8710727b437dd067d9e7233e070864551dbc9ee24f9675df99b6e95f22c3bb326e1e2b716b9fa59fc291a1
ssdeep: 24576:5HLmCiIhiXLd6xl0bbdK+5jcG9y+6HK6GrDEm/ZjXarW/w5QLTOFEhY+hlMoJluI:q+0bH9cAybGD3jX6WAaR7gSPvDBoM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.FIL also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45293966
FireEyeGeneric.mg.9ed9f7afabfb8053
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 0056eb2e1 )
AlibabaTrojanSpy:MSIL/Quasar.0803cf07
K7GWTrojan-Downloader ( 0056eb2e1 )
Cybereasonmalicious.054e47
CyrenW32/Trojan.MTCS-6636
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.MSIL.Quasar.kbw
BitDefenderTrojan.GenericKD.45293966
Paloaltogeneric.ml
AegisLabTrojan.MSIL.Quasar.l!c
RisingHackTool.MinerAccTool!1.C599 (CLASSIC)
Ad-AwareTrojan.GenericKD.45293966
SophosMal/Generic-S (PUA)
ComodoMalware@#17dhyhlb6xymp
F-SecureTrojan.TR/Dldr.Agent.cxxfx
TrendMicroTROJ_GEN.R011C0WA521
McAfee-GW-EditionBehavesLike.Win32.Suspicioustrojan.vc
EmsisoftTrojan.GenericKD.45293966 (B)
IkarusTrojan-Downloader.Win32.Agent
GDataTrojan.GenericKD.45293966
AviraTR/Dldr.Agent.cxxfx
MAXmalware (ai score=86)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2B3218E
ZoneAlarmTrojan-Spy.MSIL.Quasar.kbw
MicrosoftTrojan:Win32/Ymacco.AA91
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.45293966
VBA32TrojanSpy.MSIL.Quasar
MalwarebytesSpyware.RedLineStealer
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FIL
TrendMicro-HouseCallTROJ_GEN.R002H0DA121
TencentWin32.Trojan-downloader.Agent.Hytt
YandexTrojanSpy.Keylogger!ItyKXsB5VxE
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Agent.FIL!tr.dldr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Generic/Trojan.Spy.8a1

How to remove Win32/TrojanDownloader.Agent.FIL?

Win32/TrojanDownloader.Agent.FIL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment