Trojan

About “Trojan.Agent.FEZO” infection

Malware Removal

The Trojan.Agent.FEZO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FEZO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Thai
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Trojan.Agent.FEZO?


File Info:

name: 5A484EDA273340117B74.mlw
path: /opt/CAPEv2/storage/binaries/1b81bde6f0b3e34eebf257ce8db071811e3a623ceff66d723866682b9016806d
crc32: A8C210CB
md5: 5a484eda273340117b749481138abf6a
sha1: f3e6e0fec5f66a5f76540d760ccc218127bc14ab
sha256: 1b81bde6f0b3e34eebf257ce8db071811e3a623ceff66d723866682b9016806d
sha512: 3f2ad6522055e69ca07646187dcc6bdd35e4f505e3fe82c080f9bd9342a30ccc72ea8278213714b89285acd7dd37ae92f29e20151e8143cdfebcc9b880ba9a88
ssdeep: 12288:kxVoNgutTSbgyKa0jrYR8gkThAlSfPboMwKWAfjW:kAX2bgmlkTh3fPb6A7W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18CE47D00BBD4CE63E85F87345521C25D26BAFD605B659293728DBB9E0CBB3A01B37361
sha3_384: 7a0486548e4921ab1710581d1cfadb9ab3300baa1657b9b97e3f4b1fe2df3cf0ba6fc5f25b028d0a03a02fac26fd1f03
ep_bytes: e889730000e979feffff8bff558bec8b
timestamp: 2020-10-02 08:00:37

Version Info:

FileVerus: 1.0.2.18
ProductVersys: 1.5.28.29
Translations: 0x0126 0x03de

Trojan.Agent.FEZO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.FEZO
FireEyeGeneric.mg.5a484eda27334011
CAT-QuickHealTrojan.AgentPMF.S19738869
McAfeePacked-GDK!5A484EDA2733
MalwarebytesTrojan.MalPack.GS
ZillyaTrojan.Kryptik.Win32.3009983
K7AntiVirusTrojan ( 0057a0e81 )
K7GWTrojan ( 0057a0e81 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34084.OqZ@aSBnRTnG
CyrenW32/Glupteba.R.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKFP
APEXMalicious
ClamAVWin.Malware.Ffam-9851237-0
KasperskyHEUR:Trojan.Win32.Agent.vho
BitDefenderTrojan.Agent.FEZO
NANO-AntivirusTrojan.Win32.Bingoml.itiotc
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazp1mqAWxgtM0qI1f2i1iDso)
Ad-AwareTrojan.Agent.FEZO
SophosTroj/Agent-BGWM
DrWebTrojan.DownLoader38.19542
TrendMicroBackdoor.Win32.GLUPTEBA.SMTH.hp
McAfee-GW-EditionPacked-GDK!5A484EDA2733
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.FEZO
JiangminTrojan.Agent.dfny
AviraHEUR/AGEN.1142697
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Agent.FEZO
MicrosoftTrojan:Win32/Ranumbot.GR!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Glupteba.R395070
Acronissuspicious
VBA32Malware-Cryptor.Azorult.gen
ALYacTrojan.Agent.FEZO
CylanceUnsafe
TrendMicro-HouseCallBackdoor.Win32.GLUPTEBA.SMTH.hp
TencentMalware.Win32.Gencirc.11d6f363
YandexTrojan.Agent!AHulSrt+LpA
IkarusTrojan-Banker.UrSnif
FortinetW32/Kryptik.HKGD!tr
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.ec5f66
AvastWin32:BotX-gen [Trj]
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Agent.FEZO?

Trojan.Agent.FEZO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment