Trojan

MSIL/TrojanDropper.Agent.FEC malicious file

Malware Removal

The MSIL/TrojanDropper.Agent.FEC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.FEC virus can do?

  • Authenticode signature is invalid

How to determine MSIL/TrojanDropper.Agent.FEC?


File Info:

name: BB77EC9CF01E383AFB15.mlw
path: /opt/CAPEv2/storage/binaries/46acee738980587cca767a028d95452ea818d7c534401bab693a9f8bfa818929
crc32: 7F31A34C
md5: bb77ec9cf01e383afb15743af3316416
sha1: d79cd7e9693560a0b9e7ba678c3bb9b1e5b353be
sha256: 46acee738980587cca767a028d95452ea818d7c534401bab693a9f8bfa818929
sha512: 446ad3330bdccc0c7fe349c59c42348d16c63f70b23feb1e5048ee04edda85b26c26270826dded965a0ff2e938b316735ba0abab561635a5e884b7f300498c0c
ssdeep: 49152:zeRZumReniFB8mOPeTsuHJQVtG0lJq5dy6f0KJxq8fZi:a8maiMmOP+DkIdf8KJw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145B5CF48E2E1A63B87C67D697A15287CC2C67C879AD222B0D404C9E6E4F7FD90539C73
sha3_384: e686e822b6d097446331f7fcf121987c15a66124bf14c304b436610a2b464908069c75a8aee1c48ce6cd96608000f14d
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-11-30 20:05:38

Version Info:

Translation: 0x0000 0x04b0
Comments: Host Process for Windows Services
CompanyName: Microsoft Corporation
FileDescription: Windows Update Assistant
FileVersion: 10.0.18362.1
InternalName: BlackBinderStub.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: BlackBinderStub.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.18362.1
Assembly Version: 10.0.18362.1

MSIL/TrojanDropper.Agent.FEC also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Siggen11.58603
MicroWorld-eScanGen:Variant.Razy.827016
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeGenericRXNA-WA!BB77EC9CF01E
MalwarebytesBackdoor.AsyncRAT
VIPREGen:Variant.Razy.827016
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.cf01e3
BitDefenderThetaGen:NN.ZemsilF.36250.oo0@amyHDcc
CyrenW32/MSIL_Agent.FCS.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FEC
APEXMalicious
KasperskyHEUR:Trojan.MSIL.NetWire.gen
BitDefenderGen:Variant.Razy.827016
AvastWin32:RATX-gen [Trj]
EmsisoftGen:Variant.Razy.827016 (B)
F-SecureTrojan.TR/Drop.Agent.erinf
TrendMicroTROJ_GEN.R014C0PF923
McAfee-GW-EditionBehavesLike.Win32.Generic.vm
FireEyeGeneric.mg.bb77ec9cf01e383a
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.827016
JiangminTrojan.Generic.gpira
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Drop.Agent.erinf
MAXmalware (ai score=89)
ArcabitTrojan.Razy.DC9E88
ZoneAlarmHEUR:Trojan.MSIL.NetWire.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C4264328
ALYacGen:Variant.Razy.827016
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R014C0PF923
IkarusWorm.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.FEC!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/TrojanDropper.Agent.FEC?

MSIL/TrojanDropper.Agent.FEC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment