Trojan

Trojan.Agent.FFVY (B) removal guide

Malware Removal

The Trojan.Agent.FFVY (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FFVY (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.FFVY (B)?


File Info:

name: 57B907DE5EB3C01B86B8.mlw
path: /opt/CAPEv2/storage/binaries/1e4e4cbb5f88d75b1711001d64ea6790d32bcdd0480bdabec5c55f79f777c4c6
crc32: 9B3A92E2
md5: 57b907de5eb3c01b86b8af260ee98425
sha1: ab3e215f72462e9116ad8780ca7704bc9c18864c
sha256: 1e4e4cbb5f88d75b1711001d64ea6790d32bcdd0480bdabec5c55f79f777c4c6
sha512: 23e5b7f453bcfc0520191949b38c8bb143eb4ef781ada230f7346686d5b2db6d67690587ee8c25bce4e5e6eda56b2889a2a92933c2213f8355f44119c8d46889
ssdeep: 1536:BBsz65Y1hRO/N69BH3OoGa+FL9jKceRgrkjSo3E:7G4Y1hkFoN3Oo1+F92SP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110C3CDAAFB82107DF156007C17DAE6F337A674459D6BD08AA734B2A40CDAD1108FDB63
sha3_384: 74c26af4977e3f90a58c14d180a15310be5e3e4551857ea53d8805301dd6606dbdb3efbc806f73421d1e27051ac0010f
ep_bytes: 6880124000e8eeffffff000048000000
timestamp: 2012-04-10 21:59:09

Version Info:

0: [No Data]

Trojan.Agent.FFVY (B) also known as:

BkavW32.FamVT.JorikHQc.Trojan
LionicWorm.Win32.Vobfus.o!c
MicroWorld-eScanTrojan.Agent.FFVY
ClamAVWin.Dropper.XtremeRAT-7708589-0
FireEyeGeneric.mg.57b907de5eb3c01b
CAT-QuickHealTrojan.Beebone.D
ALYacTrojan.Agent.FFVY
Cylanceunsafe
ZillyaTrojan.JorikGen.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/vobfus.12e3e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e5eb3c
BaiduWin32.Worm.Autorun.u
VirITTrojan.Win32.Generic.KN
CyrenW32/Vobfus.AO.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.Agent.ATZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.aiez
BitDefenderTrojan.Agent.FFVY
NANO-AntivirusTrojan.Win32.Autoruner.cihufu
SUPERAntiSpywareWorm.Vobfus
AvastWin32:VB-ACGX [Trj]
TencentWorm.Win32.Vobfus.ka
TACHYONWorm/W32.Vobfus.126976
EmsisoftTrojan.Agent.FFVY (B)
F-SecureTrojan.TR/Jorik.Vobfus.ajr
DrWebWin32.HLLW.Autoruner2.29121
VIPRETrojan.Agent.FFVY
TrendMicroTROJ_AGENT_031859.TOMB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminemalicious.high.ml.score
SophosTroj/Vb-FWD
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.FFVY
JiangminTrojan/Jorik.gjym
AviraTR/Jorik.Vobfus.ajr
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AD@4omzqe
ArcabitTrojan.Agent.FFVY
ViRobotTrojan.Win32.Vobfus.126976
ZoneAlarmWorm.Win32.Vobfus.aiez
MicrosoftWorm:Win32/Vobfus.EK
GoogleDetected
AhnLab-V3Trojan/Win32.Vobfus.R37780
Acronissuspicious
McAfeeVBObfus.ds
MAXmalware (ai score=81)
VBA32SScope.Malware-Cryptor.VBCR.1141
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_AGENT_031859.TOMB
RisingWorm.VobfusEx!1.99E1 (CLASSIC)
YandexTrojan.GenAsa!NQ5jghRmwiA
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36196.hmW@aeY4N6i
AVGWin32:VB-ACGX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.FFVY (B)?

Trojan.Agent.FFVY (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment