Trojan

BAT/TrojanDropper.Agent.NFZ malicious file

Malware Removal

The BAT/TrojanDropper.Agent.NFZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/TrojanDropper.Agent.NFZ virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

How to determine BAT/TrojanDropper.Agent.NFZ?


File Info:

crc32: 2BB7C2CB
md5: 3f44da96dca4bd2755c6194a9c87941e
name: 3F44DA96DCA4BD2755C6194A9C87941E.mlw
sha1: 04d69b1dcfee7a2dbb4e26d3185a338feef80e93
sha256: 0545ebd59cb8329a72617377c14b8d8e44fead767651397befaf4f0ceddda4ad
sha512: 15b14eb80ea17fb9571aa5dacb972e42c49b69cad91fcd0f669d495babfb74f137362aaa567bcaf06b0bfba1006105c915c404f3db5ca2c6e43486e4e4986130
ssdeep: 49152:25+hFVhgHYurvLIxJItN6fFsa2ez8bIcqgZii5uYP3hfBYOESxiz8lVHTIioOFZ4:25aFVhy70gIFsfLIcqgZiiEYfh7xiqZ4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2003-2010 Lavalys, Inc.
InternalName: EVEREST
FileVersion: 5.50.2100.0
CompanyName: Lavalys, Inc.
Builder: Alex 11:07:42 03/06/2021
Created: 7z SFX Constructor v4.5.0.0 (http://usbtor.ru/viewtopic.php?t=798)
ProductName: EVEREST Ultimate Edition
ProductVersion: 5.50.2100.0
FileDescription: EVEREST Ultimate Edition
OriginalFilename: everest.exe
Translation: 0x0000 0x04b0

BAT/TrojanDropper.Agent.NFZ also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.Starter.8002
CynetMalicious (score: 100)
ALYacGen:Variant.Spider.1
Cybereasonmalicious.6dca4b
ESET-NOD32BAT/TrojanDropper.Agent.NFZ
APEXMalicious
AvastFileRepMalware
ClamAVWin.Malware.Bulz-9866401-0
KasperskyVHO:Backdoor.Win32.Convagent.gen
BitDefenderGen:Variant.Spider.1
MicroWorld-eScanGen:Variant.Spider.1
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.3f44da96dca4bd27
EmsisoftGen:Variant.Spider.1 (B)
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Spider.1
GDataWin32.Trojan.PSE.88RA12
MAXmalware (ai score=80)
VBA32Trojan.Hesv
MalwarebytesMalware.AI.3142327239
FortinetBAT/Reline.BPP!tr
AVGFileRepMalware

How to remove BAT/TrojanDropper.Agent.NFZ?

BAT/TrojanDropper.Agent.NFZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment