Trojan

Trojan.Agent.FFVZ removal tips

Malware Removal

The Trojan.Agent.FFVZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FFVZ virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Georgian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.FFVZ?


File Info:

name: A1F3F02785100B1830B2.mlw
path: /opt/CAPEv2/storage/binaries/ab8cd2854c6cf85def2ac9d0834854488ad01b98f6d0cc8c3e35a5fbf6dc6563
crc32: 57D7B27A
md5: a1f3f02785100b1830b2489177189485
sha1: cd15f15c2dda64623116ddefaebf6227644d444e
sha256: ab8cd2854c6cf85def2ac9d0834854488ad01b98f6d0cc8c3e35a5fbf6dc6563
sha512: 13701d93222ebe003e85cda6b274337d07f17e210df388c50626c47ddb7db377664455d578a8528bbc15a7d5b68c599502af3b748433425fd45711fceb9cb523
ssdeep: 6144:4mTbbrqPxefpUnEFGLwsPpeeDxhfUGUAoSz:7bbrMIfCoG0sPpPDoGDoSz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18684F14CE48AD0A7C9E602F6789587D3831C564C233B285F2B1EAB1B65A15CF0D60BED
sha3_384: 35b8a04bec863dd3fa3f088e498fbbaf4064bdd46d62a2131b0d4ddc14d09013497cceed38bda8c8d92308211ebad5f9
ep_bytes: 6a7068d8f14200e8de01000033db538b
timestamp: 2005-07-22 07:21:35

Version Info:

Comments:
CompanyName: Microsoft Bursting
FileDescription: Complimented
FileVersion: 223, 80, 127, 250
InternalName: Vocals
LegalCopyright: Copyright © 2014
LegalTrademarks:
OriginalFilename: Ban.exe
PrivateBuild:
ProductName: Microsoft Caseload
ProductVersion: 8, 76, 123, 154
SpecialBuild:

Trojan.Agent.FFVZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.mAsy
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader17.28491
MicroWorld-eScanTrojan.Agent.FFVZ
ClamAVWin.Packed.Ursu-7372399-0
McAfeeGenericRXGO-XM!A1F3F0278510
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Androm.Win32.27664
SangforSuspicious.Win32.Save.ins
K7AntiVirusSpyware ( 004cfca41 )
AlibabaTrojan:Win32/Vawtrak.90dd
K7GWSpyware ( 004cfca41 )
Cybereasonmalicious.c2dda6
CyrenW32/S-60965296!Eldorado
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.Agent.FFVZ
AvastWin32:Shifu-D [Trj]
TencentMalware.Win32.Gencirc.10bb84a8
EmsisoftTrojan.Agent.FFVZ (B)
VIPRETrojan.Agent.FFVZ
McAfee-GW-EditionBehavesLike.Win32.Fake.fm
FireEyeTrojan.Agent.FFVZ
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.FFVZ
JiangminTrojan.Generic.jmb
MAXmalware (ai score=81)
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumTrojWare.Win32.Spy.Shiz.ND@6uylou
ArcabitTrojan.Agent.FFVZ
MicrosoftBackdoor:Win32/Vawtrak
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2486673
Acronissuspicious
ALYacTrojan.Agent.FFVZ
Cylanceunsafe
PandaTrj/CI.A
RisingBackdoor.Vawtrak!1.AE6A (CLASSIC)
IkarusBackdoor.Win32.Vawtrak
MaxSecureTrojan.Malware.7454948.susgen
AVGWin32:Shifu-D [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.FFVZ?

Trojan.Agent.FFVZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment