Trojan

Win32/TrojanDownloader.Agent.FLW removal tips

Malware Removal

The Win32/TrojanDownloader.Agent.FLW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.FLW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/TrojanDownloader.Agent.FLW?


File Info:

name: F88DCC451090934239F8.mlw
path: /opt/CAPEv2/storage/binaries/b6dcccaa822ae1d707554885fb4f4d96a8e647b6fd0c440b55dbd5c02085cd41
crc32: AC618496
md5: f88dcc451090934239f8ebee6f27989b
sha1: 24e4e9fa658b98edd9f12b9ac8e41c76311ec7fb
sha256: b6dcccaa822ae1d707554885fb4f4d96a8e647b6fd0c440b55dbd5c02085cd41
sha512: 41540434cea7abc5ea857dea09518ebec5b69bc9aa7ce4829c98bdde001faa47b3e32e8a878c5ad5e380b2d92e33f3e33e065de481664e2113c41a8b92a72bfd
ssdeep: 393216:8Roj/LbO89GjFkVzEOMvT9b+RQFfOPsVyIc/coKdzm:8YO89GjFOzUvpb+RQFGSyIc/wxm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14CE633D5EBEF2B38F02856B347C7497B8659BFA554914E2F1047F6C2A7341C22E8242B
sha3_384: ad0c8fc21741232f5d803d3df7e3646926e06453b875365ea8bb3b1ad3e461c22078c92281b010e222c1faa39724f8b1
ep_bytes: 680140c201e801000000c3c3fb570e01
timestamp: 2020-12-25 15:40:28

Version Info:

CompanyName: Audit.digital s.r.o.
FileDescription: Erida installer
FileVersion: 1.0.0.0
InternalName: Setup.exe
LegalCopyright: Copy (c) 2020 Audit.digital s.r.o.
LegalTrademarks: Audit.digital s.r.o.
OriginalFilename: Setup.exe
ProductName: Erida installer
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04b0

Win32/TrojanDownloader.Agent.FLW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36030874
FireEyeGeneric.mg.f88dcc4510909342
ALYacTrojan.GenericKD.36030874
CylanceUnsafe
ZillyaDownloader.Agent.Win32.425255
Sangfor[ASPROTECT V2.X REGISTERED -> ALEXEY SOLODOVNIKOV]
K7AntiVirusTrojan-Downloader ( 00575b701 )
BitDefenderTrojan.GenericKD.36030874
K7GWTrojan-Downloader ( 00575b701 )
ArcabitTrojan.Generic.D225C99A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FLW
APEXMalicious
Paloaltogeneric.ml
AlibabaTrojanDownloader:Win32/AdwareSig.518c38a9
RisingTrojan.Generic@AI.100 (RDML:tlqMM1hHBYqt1Z2ODE3IPg)
Ad-AwareTrojan.GenericKD.36030874
EmsisoftTrojan.GenericKD.36030874 (B)
F-SecureHeuristic.HEUR/AGEN.1215815
DrWebTrojan.MulDrop14.725
VIPRETrojan.GenericKD.36030874
McAfee-GW-EditionArtemis!PUP
SophosMal/Generic-S
IkarusTrojan.Win32.Generic
AviraHEUR/AGEN.1215815
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.36030874
GoogleDetected
McAfeeArtemis!F88DCC451090
MalwarebytesAdware.Agent
PandaTrj/CI.A
FortinetW32/GenCBL.SJ!tr
AVGWin32:AdwareSig [Adw]
Cybereasonmalicious.510909
AvastWin32:AdwareSig [Adw]

How to remove Win32/TrojanDownloader.Agent.FLW?

Win32/TrojanDownloader.Agent.FLW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment