Trojan

Trojan.Agent.FDDF removal instruction

Malware Removal

The Trojan.Agent.FDDF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FDDF virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications

How to determine Trojan.Agent.FDDF?


File Info:

crc32: 57130ECA
md5: cb9714bbb1be0f7f06ed9c183b4f5069
name: CB9714BBB1BE0F7F06ED9C183B4F5069.mlw
sha1: f818b46aa9f494f70fb6f1bbdd45c5a0ab0adc7f
sha256: 2bfac044fc97e0b62ffdad9b79246dc76ce380faa90308ffb1c020b9406dd890
sha512: 2ecc232fd79d6fea126d802d1aff93d99a95e264d0950e7268644a47925c10446609a02639ef15cac9b7e00dcdd0b2cabafb5541ca4c6820fb2916f0f036a3fe
ssdeep: 3072:D+rGFFRCMcyzAAykMPqIaXpZYnvf3gx4wblxLSoIm/H2QKGB2gC:D+rGFFlXAAcqj8nHgfOoIdG
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2006 The PHP Group
InternalName: php_curl.dll
FileVersion: 5.2.0.0
CompanyName: The PHP Group
URL: http://www.php.net
PrivateBuild:
LegalTrademarks: PHP
Comments: Thanks to Sterling Hughes
ProductName: PHP php_curl.dll
SpecialBuild:
ProductVersion: 5.2.0
FileDescription: cURL
OriginalFilename: php_curl.dll
Translation: 0x0409 0x04b0

Trojan.Agent.FDDF also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.55725
MicroWorld-eScanTrojan.Agent.FDDF
FireEyeGeneric.mg.cb9714bbb1be0f7f
McAfeeGenericRXAA-AA!CB9714BBB1BE
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/EmotetedCryptc.180910
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Agent.FDDF
BitDefenderThetaGen:NN.ZedlaF.34804.ku8@aGRuH!ji
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Agent.FDDF
Paloaltogeneric.ml
RisingTrojan.Generic@ML.100 (RDML:sEtt02xTL9HyihRqsvFRAg)
Ad-AwareTrojan.Agent.FDDF
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Crypt.Agent.kujny
McAfee-GW-EditionBehavesLike.Win32.Drixed.cc
SophosML/PE-A
IkarusTrojan-Banker.Dridex
AviraTR/Crypt.Agent.kujny
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Dridex.CG!MSR
AegisLabTrojan.Win32.Malicious.4!c
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.Agent.FDDF
CynetMalicious (score: 100)
Acronissuspicious
MAXmalware (ai score=88)
MalwarebytesMalware.Heuristic.1001
ESET-NOD32a variant of Win32/Kryptik.HJJX
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HJJX!tr
AVGWin32:BankerX-gen [Trj]

How to remove Trojan.Agent.FDDF?

Trojan.Agent.FDDF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment