Categories: Trojan

Trojan.Agent.CZFN removal

The Trojan.Agent.CZFN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CZFN virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Agent.CZFN?


File Info:

crc32: DDF327BDmd5: d0ffa004e131c2cda0d7e45c585741c1name: 1.exesha1: 62b61b2addb2f95ad0bb98f60cf8e5b05c2cfdacsha256: 9669a9e64c78110de2c26d1cc53fede364bbf39bc91097e7d4d13ec9c7762e37sha512: 5e217a34fe10a0736ff27537f96b6427c619ab3ecd804825d70721c002b82a7138e8b3dc6d02f542788122cfa0466d01cdc409bd7fbde55f2df4bb5c39aec0bdssdeep: 24576:cmTSRtiFW2lyAP8hDkDSiUXo8D+0OQLUKx1Xdt:cm60P8pF4iLLdtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.CZFN also known as:

MicroWorld-eScan Trojan.Agent.CZFN
FireEye Generic.mg.d0ffa004e131c2cd
Qihoo-360 Win32/Trojan.680
McAfee Fareit-FLN!D0FFA004E131
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Malware
K7AntiVirus Trojan ( 00531b081 )
BitDefender Trojan.Agent.CZFN
K7GW Trojan ( 00531b081 )
Cybereason malicious.4e131c
TrendMicro TSPY_HPLOKI.SMBD
BitDefenderTheta Gen:NN.ZelphiF.34106.dHW@aevNdkdi
F-Prot W32/Trojan3.AMLB
Symantec Trojan.Gen.2
ESET-NOD32 a variant of Win32/Injector.DYBC
TrendMicro-HouseCall TSPY_HPLOKI.SMBD
Avast Win32:Dropper-gen [Drp]
GData Trojan.Agent.CZFN
Kaspersky HEUR:Backdoor.Win32.Generic
NANO-Antivirus Trojan.Win32.Stealer.fcamcg
AegisLab Trojan.Win32.Generic.m!c
APEX Malicious
Rising Trojan.Injector!1.AFE3 (CLASSIC)
Endgame malicious (high confidence)
Emsisoft Trojan.Agent.CZFN (B)
Comodo Malware@#3n1n5xvz1dhqv
F-Secure Heuristic.HEUR/AGEN.1033899
DrWeb Trojan.PWS.Stealer.23180
Zillya Dropper.Injector.Win32.84698
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.Fareit.tc
Trapmine malicious.high.ml.score
Sophos Mal/Fareit-Q
Cyren W32/Trojan.YSXH-7838
Jiangmin Backdoor.Generic.ardg
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1104985
MAX malware (ai score=99)
Antiy-AVL Trojan/Win32.TSGeneric
Microsoft VirTool:Win32/CeeInject.ADU!bit
Arcabit Trojan.Agent.CZFN
SUPERAntiSpyware Trojan.Agent/Gen-Downloader
AhnLab-V3 Win-Trojan/Delphiless.Exp
ZoneAlarm HEUR:Backdoor.Win32.Generic
Acronis suspicious
VBA32 TrojanPSW.Stealer
ALYac Trojan.Agent.CZFN
Ad-Aware Trojan.Agent.CZFN
Malwarebytes Spyware.LokiBot
Panda Trj/CI.A
Zoner Trojan.Win32.67200
Tencent Malware.Win32.Gencirc.10b3afd5
Yandex Trojan.Injector!AD1b4kdpQFc
Ikarus Trojan.Win32.Injector
eGambit Unsafe.AI_Score_99%
Fortinet W32/Injector.DXRU!tr
AVG Win32:Dropper-gen [Drp]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.7175197.susgen

How to remove Trojan.Agent.CZFN?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Worm:Win32/Korgo.V”?

The Worm:Win32/Korgo.V is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago

Worm.Win32.Vobfus.dlcn (file analysis)

The Worm.Win32.Vobfus.dlcn is considered dangerous by lots of security experts. When this infection is active,…

10 mins ago

Win32/Adware.InternetAntivirus removal instruction

The Win32/Adware.InternetAntivirus is considered dangerous by lots of security experts. When this infection is active,…

10 mins ago

TrojanDownloader:Win32/Unruy.A removal instruction

The TrojanDownloader:Win32/Unruy.A is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

Trojan:MSIL/Zusy.RDF!MTB removal guide

The Trojan:MSIL/Zusy.RDF!MTB is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

About “Win32:Sality-KYG” infection

The Win32:Sality-KYG is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago