Trojan

MSIL/TrojanDownloader.Agent.FFB removal

Malware Removal

The MSIL/TrojanDownloader.Agent.FFB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.FFB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/TrojanDownloader.Agent.FFB?


File Info:

crc32: 904B1259
md5: b9648820887884bb6f726a31c0f4bc5f
name: autoupdatepface.exe
sha1: e8ae77adcc004de2d0c2bdb182637bc2215438f8
sha256: d466ef7a7bac7548efbf38f024c6599b82dcd9d7c92a38ded5efc28a573eec89
sha512: 8f1d5ad3b4f8ec580dd29674ae9c947e19986878eea061fba2040da0f648e91db2635c91e2f8c90365da7e4385bdb4f2e2befa5629ad3f7c18e6e76bd0f1b239
ssdeep: 3072:k6hyLB8WH3u9FvvPPaTlLHJFvvPPmTlrHc2+:k6+B8WHgvPPaTljnvPPmTlDH+
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 10.0.0.0
InternalName: AutoUpdatePface.exe
FileVersion: 10.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: pface
ProductVersion: 10.0.0.0
FileDescription: pface
OriginalFilename: AutoUpdatePface.exe

MSIL/TrojanDownloader.Agent.FFB also known as:

MicroWorld-eScanTrojan.GenericKD.33533364
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
AegisLabTrojan.Win32.Perseus.4!c
SangforMalware
BitDefenderTrojan.GenericKD.33533364
Cybereasonmalicious.088788
ArcabitTrojan.Generic.D1FFADB4
BitDefenderThetaGen:NN.ZemsilF.34100.pm0@aGQCq0p
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.FFB
TrendMicro-HouseCallTROJ_GEN.R002C0PCB20
Paloaltogeneric.ml
AlibabaTrojan:MSIL/ulybh.8a8f2cab
RisingDownloader.Agent!8.B23 (CLOUD)
Ad-AwareTrojan.GenericKD.33533364
EmsisoftTrojan.GenericKD.33533364 (B)
ComodoMalware@#21j7479ubb29q
F-SecureTrojan.TR/Dldr.Agent.ulybh
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PCB20
McAfee-GW-EditionRDN/Generic Downloader.x
FortinetMSIL/Agent.FFB!tr.dldr
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Agent
WebrootW32.Trojan.Gen
AviraTR/Dldr.Agent.ulybh
MAXmalware (ai score=94)
Antiy-AVLTrojan[Downloader]/MSIL.Agent
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Agent.C3318843
ALYacTrojan.GenericKD.33533364
PandaTrj/GdSda.A
APEXMalicious
YandexTrojan.DL.Agent!v62VkWvbMqo
SentinelOneDFI – Malicious PE
GDataWin32.Trojan.Agent.NDDABV
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360HEUR/QVM03.0.8053.Malware.Gen

How to remove MSIL/TrojanDownloader.Agent.FFB?

MSIL/TrojanDownloader.Agent.FFB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment