Trojan

About “Trojan.Agent.FCZE (B)” infection

Malware Removal

The Trojan.Agent.FCZE (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FCZE (B) virus can do?

  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

needforrat.hopto.org

How to determine Trojan.Agent.FCZE (B)?


File Info:

crc32: 68CBCE12
md5: 37035aa02a65b1b869898cb611d37686
name: 37035AA02A65B1B869898CB611D37686.mlw
sha1: bd9d62bac74de751f593df27d7ce4885d2bedf01
sha256: 4c01cc3dd96c524054207f6b37a334c62549857f28c0286cc8dfc30b6d388e34
sha512: a7056d998dd6205518209529d71ec3221c36651474050ffe67c1356f72bc230cac055279dc13dba5e3458979a0e394499ef8cb20b02a357ccea02f1104e27655
ssdeep: 3072:bOzPcXa+ND32eioGHlz8rnAE0HCXh0edLvnoYMjMqqDvFfCZjx:bOTcK+NrRioGHlz8rz0i/ozQqqDvFfk1
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.FCZE (B) also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Wirenet.557
ClamAVWin.Dropper.NetWire-8025706-0
ALYacBackdoor.RAT.Netwire
CylanceUnsafe
ZillyaTrojan.Weecnaw.Win32.761
SangforTrojan.Win32.Save.a
K7GWSpyware ( 0055216c1 )
K7AntiVirusSpyware ( 0055216c1 )
SymantecInfostealer
ESET-NOD32a variant of Win32/Spy.Weecnaw.P
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.NetWire.gen
BitDefenderTrojan.Agent.FCZE
NANO-AntivirusTrojan.Win32.Wirenet.hlbptg
MicroWorld-eScanTrojan.Agent.FCZE
TencentMalware.Win32.Gencirc.10ce3933
Ad-AwareTrojan.Agent.FCZE
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34110.kCX@aK5Ze4d
McAfee-GW-EditionGenericRXKH-LK!37035AA02A65
FireEyeGeneric.mg.37035aa02a65b1b8
EmsisoftTrojan.Agent.FCZE (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.NetWiredRC.bld
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_84%
Antiy-AVLTrojan/Generic.ASMalwS.309056C
MicrosoftBackdoor:Win32/Netwire.PA!MTB
GridinsoftRansom.Win32.Wacatac.oa!s1
ArcabitTrojan.Agent.FCZE
GDataWin32.Trojan.Netwire.C
AhnLab-V3Trojan/Win32.RL_NetWiredRC.R342610
McAfeeGenericRXKH-LK!37035AA02A65
MAXmalware (ai score=82)
VBA32BScope.TrojanSpy.Loyeetro
MalwarebytesBackdoor.Quasar
RisingBackdoor.NetWire!1.C98D (CLASSIC)
YandexTrojan.GenAsa!DOgbQEDHp9A
IkarusBackdoor.Rat.Netwire
FortinetW32/Ulise.103681!tr
AVGWin32:RATX-gen [Trj]

How to remove Trojan.Agent.FCZE (B)?

Trojan.Agent.FCZE (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment