Trojan

MSIL/TrojanDropper.Agent.FFZ removal

Malware Removal

The MSIL/TrojanDropper.Agent.FFZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Agent.FFZ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.

How to determine MSIL/TrojanDropper.Agent.FFZ?


File Info:

crc32: 85093222
md5: f12f917eb4c9d7fe29809b04dd3f1a97
name: F12F917EB4C9D7FE29809B04DD3F1A97.mlw
sha1: 52598331a1148d6a5a8a2dfc7ffb6077833a29b9
sha256: 03db5b67aa8c5f810ada16aea81967d840ec10858aa214b8835e4c5ff9b3fbc2
sha512: 36bf828b82ea38a7c8c76838431a192de5872f69fe0badbc3ffebd48bf2d2b783cb4f2ce9abcc0097e5fbeed3cbd5e982cd762a081b714f9033b991a0526ffa9
ssdeep: 3072:TtwnL4Xcwlwbl48GUP4cMlWNJoByr2tpnkUz/jwjD2zuG:sL4Mw09PVLUtpkW/j
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: ndhavrnigh.exe
FileVersion: 1.0.0.0
ProductName: ndhavrnigh
ProductVersion: 1.0.0.0
FileDescription: ndhavrnigh
OriginalFilename: ndhavrnigh.exe

MSIL/TrojanDropper.Agent.FFZ also known as:

CynetMalicious (score: 99)
ALYacTrojan.GenericKD.37122128
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1a1148
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FFZ
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan-Ransom.MSIL.Foreign.gen
BitDefenderTrojan.GenericKD.37122128
MicroWorld-eScanTrojan.GenericKD.37122128
Ad-AwareTrojan.GenericKD.37122128
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34758.lq0@a0Xo5F
FireEyeGeneric.mg.f12f917eb4c9d7fe
EmsisoftTrojan.GenericKD.37122128 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1136904
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Generic.D2367050
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKD.37122128
McAfeeArtemis!F12F917EB4C9
MAXmalware (ai score=85)
PandaTrj/GdSda.A
IkarusTrojan-Spy.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.FFZ!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove MSIL/TrojanDropper.Agent.FFZ?

MSIL/TrojanDropper.Agent.FFZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment