Trojan

Trojan.Agent.FFNS removal

Malware Removal

The Trojan.Agent.FFNS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FFNS virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.FFNS?


File Info:

name: 0C5486B50A7403BDD281.mlw
path: /opt/CAPEv2/storage/binaries/761c49fee024ba449ed677fd3e87273769bef29c2aaf8e509e2480c74832c324
crc32: 93BDB5A7
md5: 0c5486b50a7403bdd2810e62c68a0df2
sha1: 27a70920ddd0022c606dbf703b5c5a2d573641c2
sha256: 761c49fee024ba449ed677fd3e87273769bef29c2aaf8e509e2480c74832c324
sha512: 5325b083cd92d17c53d5a76ec8cfdedd086bb9e611e8c4e191832571c201b08d23f819c4e8726aaaa185b203e9767b6e817b857704d490a579fd51c32ff53cf4
ssdeep: 6144:h3EtBeJO4v9yMEMx0yegK2T8aKoWxOMSVqge4hzpRa48Zj:IK9yS0tR/3xGVne4htg9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C64F1C5E7E1329CECF8E334E355619598A07FB5739A34E781286C6A8F728F00635726
sha3_384: b2c0d50273b94c4f5655639b42882d453f74102989437369bd40a25a3cbdfd31ddd121277725e55f515e7fa9c2ead3b7
ep_bytes: 60be150049008dbeeb0ff7ffc787506f
timestamp: 2019-07-06 07:46:44

Version Info:

FileDescription: POSIX WinThreads for Windows
ProductVersion: 1, 0, 0, 0
FileVersion: 1, 0, 0, 0
InternalName: WinPthreadGC
OriginalFilename: WinPthreadGC
CompanyName: MingW-W64 Project. All rights reserved.
LegalCopyright: Copyright (C) MingW-W64 Project Members 2010-2011
Licence: ZPL
Info: http://mingw-w64.sourceforge.net/
Comment: GNU C build -- MinGW-w64 32-bit
Translation: 0x0409 0x04b0

Trojan.Agent.FFNS also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Agent.FFNS
SkyhighArtemis
McAfeeArtemis!0C5486B50A74
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
ArcabitTrojan.Agent.FFNS
ESET-NOD32Win32/Agent.VAX
CynetMalicious (score: 99)
APEXMalicious
BitDefenderTrojan.Agent.FFNS
AvastWin32:Malware-gen
EmsisoftTrojan.Agent.FFNS (B)
F-SecureTrojan.TR/Agent.ulrcb
VIPRETrojan.Agent.FFNS
Trapminemalicious.high.ml.score
FireEyeTrojan.Agent.FFNS
IkarusTrojan.Win32.Agent
AviraTR/Agent.ulrcb
Antiy-AVLTrojan[Backdoor]/Win32.Godlua
GDataTrojan.Agent.FFNS
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R325320
ALYacTrojan.Agent.FFNS
MAXmalware (ai score=85)
MalwarebytesMachineLearning/Anomalous.97%
PandaGeneric Suspicious
RisingTrojan.Zpevdo!8.F912 (C64:YzY0OlHPsKJrc4X7)
YandexTrojan.GenAsa!kNfMK3Z3KjA
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74435034.susgen
BitDefenderThetaGen:NN.ZexaF.36792.tm0@aKKaFlki
AVGWin32:Malware-gen
Cybereasonmalicious.0ddd00
DeepInstinctMALICIOUS

How to remove Trojan.Agent.FFNS?

Trojan.Agent.FFNS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment