Trojan

Should I remove “Win32/TrojanDownloader.Agent.FSC”?

Malware Removal

The Win32/TrojanDownloader.Agent.FSC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.FSC virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Starts servers listening on 127.0.0.1:0
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself

Related domains:

note.youdao.com
ocsp.dcocsp.cn

How to determine Win32/TrojanDownloader.Agent.FSC?


File Info:

crc32: 83B82486
md5: 2cd38e96cd017364a49f9021af5d498f
name: 2CD38E96CD017364A49F9021AF5D498F.mlw
sha1: 1de4d95be8288432418c5a08e87d31063f2d9da6
sha256: 20850960658424670864f4e4a94f2537029b9d8832026b4112225d419e604b97
sha512: 2523629aa90f8dfc65662b6ddd59882f17c1cedcf022783b2e0ba4f1732a02dcd9f0b39d09fc5488eb4a229c017eedb9ad6a02bd4872cdde50383f599a22236c
ssdeep: 24576:u9s9VNjlLhcHgG9bIyD9PqN4jzKuXs1CAQx91j0IcAHdQxAd6C:Gs9VNjlLhcHgUMynPUoFx91jjcAqAd6C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Shanghai lantern science and technology co., LTD 2014
InternalName: Protecti.exe
FileVersion: 1.0.1.0
CompanyName: x4e0ax6d77x8fdex5c1ax79d1x6280x6709x9650x516cx53f8
ProductName: WiFix4e07x80fdx94a5x5319
ProductVersion: 1.0.1.0
FileDescription: WiFix4e07x80fdx94a5x5319
OriginalFilename: Protecti.exe
Translation: 0x0804 0x04b0

Win32/TrojanDownloader.Agent.FSC also known as:

CynetMalicious (score: 100)
ALYacGen:Variant.Doina.16391
CylanceUnsafe
Cybereasonmalicious.be8288
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FSC
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Lotok.gen
BitDefenderGen:Variant.Doina.16391
MicroWorld-eScanGen:Variant.Doina.16391
Ad-AwareGen:Variant.Doina.16391
BitDefenderThetaGen:NN.ZexaF.34744.6u1@a4vuSGpj
FireEyeGen:Variant.Doina.16391
EmsisoftGen:Variant.Doina.16391 (B)
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Doina.D4007
GDataGen:Variant.Doina.16391
McAfeeGenericRXOW-ZQ!2CD38E96CD01
MAXmalware (ai score=88)
VBA32BScope.Backdoor.Lotok
PandaTrj/GdSda.A
IkarusPUA.OpenSUpdater
AVGWin32:MalwareX-gen [Trj]

How to remove Win32/TrojanDownloader.Agent.FSC?

Win32/TrojanDownloader.Agent.FSC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment