Trojan

MSIL/TrojanDownloader.Agent.KFZ removal

Malware Removal

The MSIL/TrojanDownloader.Agent.KFZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.KFZ virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.KFZ?


File Info:

name: 83E6BAA05C485BD2512B.mlw
path: /opt/CAPEv2/storage/binaries/43c223d3541394e6be305501b243ba8975be2d38b5a6fbd7f239068ccc5afe30
crc32: 69360B7B
md5: 83e6baa05c485bd2512b3e534b513208
sha1: d0f62de51af7a8c1a93fb41922fb6e2a2f1909e4
sha256: 43c223d3541394e6be305501b243ba8975be2d38b5a6fbd7f239068ccc5afe30
sha512: d24bd29849f9e1374e518a037c422b1c2e2000a7df5e518da3d88be6f4ad4b5d377de1d709b84059301b59f446af9d1885f56e56b3bfa89891a4b0e7c6cc7f99
ssdeep: 96:ve6Aa0FjRRTBZL9H71UyRZj4DAGq4LnLakdaSVoRvUf0SVLSQv2ZpdIc5yzguzNt:veVfXL9b1tTs8X4LnLWSGRv6HsGQm5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13212F82BABFD8279E87A0E309863A30053F9F3458977DF6E64C0511B6D263404E52FB1
sha3_384: e371c515e135bc1c6acb6a8a706b930464d7dcc8b018de7429fa35e467fcfc638856142de4ffed2b68c7a09788a30c14
ep_bytes: ff250020400000000000000000000000
timestamp: 2080-04-28 21:34:40

Version Info:

Translation: 0x0000 0x04b0
Comments: Vi Improved - A Text Editor
CompanyName: Vim Developers
FileDescription: Vi Improved - A Text Editor
FileVersion: 8.2.4257.0
InternalName: gvim2.exe
LegalCopyright: Copyright (C) 1996
LegalTrademarks: Vim
OriginalFilename: gvim2.exe
ProductName: Vim
ProductVersion: 8.2.4257.0
Assembly Version: 8.2.4257.0

MSIL/TrojanDownloader.Agent.KFZ also known as:

LionicTrojan.MSIL.PsDownload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48286149
FireEyeGeneric.mg.83e6baa05c485bd2
McAfeeArtemis!83E6BAA05C48
CylanceUnsafe
SangforTrojan.MSIL.PsDownload.gen
K7AntiVirusTrojan-Downloader ( 0058dce31 )
AlibabaTrojanDownloader:MSIL/PsDownload.d26bbfce
K7GWTrojan-Downloader ( 0058dce31 )
Cybereasonmalicious.51af7a
BitDefenderThetaGen:NN.ZemsilF.34212.am0@auKgeXf
SymantecMSIL.Downloader!gen7
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.KFZ
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.MSIL.PsDownload.gen
BitDefenderTrojan.GenericKD.48286149
APEXMalicious
RisingMalware.Obfus/MSIL@AI.98 (RDM.MSIL:kC2iPOxUcKh730d3D9wcMw)
Ad-AwareTrojan.GenericKD.48286149
EmsisoftTrojan.GenericKD.48286149 (B)
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Agent
GDataWin32.Trojan.Agent.HY7CE7
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1232055
MAXmalware (ai score=86)
ArcabitTrojan.Generic.D2E0C9C5
ZoneAlarmHEUR:Trojan-Downloader.MSIL.PsDownload.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Sabsik.C4914941
MalwarebytesTrojan.Downloader.MSIL.Generic
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Trojan-downloader.Agent.Ecao
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FQKH!tr
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/TrojanDownloader.Agent.KFZ?

MSIL/TrojanDownloader.Agent.KFZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment