Start to remove TrojanDownloader:Win32/Agent.FI now!
TrojanDownloader:Win32/Agent.FI description and removal instruction

TrojanDownloader:Win32/Agent.FI

Free TrojanDownloader:Win32/Agent.FI Scan

Technical information
Payload
Removal instructions

Technical information

The TrojanDownloader:Win32/Agent.FI will install rogue security software TeddyPass into the affected machines without users knowledge. The TrojanDownloader:Win32/Agent.FI file size is 338432 bytes.

Payload

Once launched, the TrojanDownloader:Win32/Agent.FI performs the following actions:

  • Download rogue security tool TeddyPass from the following domains:
    https://teddypass.com/
  • Modify the properties of the following files:
    %SYSTEMROOT%:\WINDOWS\winsxs\amd64_microsoft-windows-consolehost_31bf3856ad364e35_6.1.7600.16385_none_d050b8f81bcacc5a\\conhost.exe

    (338432 bytes; detected by HitMalware as " TrojanDownloader:Win32/Agent.FI")
  • Removal instructions

    If your machine doesn't have antivirus/antispyware, please take the following steps to resolve the problems caused by TrojanDownloader:Win32/Agent.FI:

    1. Replace the infected file conhost.exe for free by using conhost.exe repair tool - DLL Suite. See how to replace conhost.exe by using DLL Suite.

    2. Perform a full TrojanDownloader:Win32/Agent.FI scan by using the latest antivirus/antispyware HitMalware.
    (Download Trial Version Now)

    MD5: 95141829514182


    How to replace conhost.exe by using DLL Suite

  • Download DLL Suite, install and run
  • Click "Start Scan" button to check conhost.exe file
  • Choose conhost.exe and click "More Information"
  • Download conhost.exe for free from the open web page
  • Save conhost.exe to its default folder to replace infected conhost.exe file.
  • Download TrojanDownloader:Win32/Agent.FI Removal Tool Now

    Download TrojanDownloader:Win32/Agent.FI Removal Tool Now