Trojan

Should I remove “Win32/TrojanDownloader.Agent.FMZ”?

Malware Removal

The Win32/TrojanDownloader.Agent.FMZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.FMZ virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs

How to determine Win32/TrojanDownloader.Agent.FMZ?


File Info:

crc32: 7A5DE37F
md5: 9aed5c0bec3cb972a2f8e3c43ee13989
name: 9AED5C0BEC3CB972A2F8E3C43EE13989.mlw
sha1: 81561b57086cfbe162cadeb97dbe159ac650f355
sha256: 6d9a242a136db1592ef7386ea2bedd833026f7947e1887732f733fd3bcd7fbb2
sha512: 09b381d5007a56edf96b3cdd92856a23a79d77185c6175dfec6b02e6c07a4387716ac9a478c99b4fa90be11af02d609683e9679c1d889becb704f17a6231e5ac
ssdeep: 1536:YfdMrcf726IyV4BwpgX2QNs1qxZwuVqFHQxCjvDptB6ihIU5Uo9SuTbg0lYq8M:Yf6rcaKWtGQNs1qzR9JvzSlbg1qN
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Www.SysCeo.Com
FileVersion: 1.0.0.0
FileDescription: FormCeo
Translation: 0x0804 0x04b0

Win32/TrojanDownloader.Agent.FMZ also known as:

MicroWorld-eScanTrojan.GenericKD.36276916
FireEyeGeneric.mg.9aed5c0bec3cb972
ALYacTrojan.GenericKD.36276916
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 005770301 )
BitDefenderTrojan.GenericKD.36276916
K7GWTrojan-Downloader ( 005770301 )
Cybereasonmalicious.7086cf
APEXMalicious
AvastWin32:Trojan-gen
AegisLabRiskware.Win32.Generic.1!c
Ad-AwareTrojan.GenericKD.36276916
F-SecureTrojan:W32/Agent.DSNN
TrendMicroTROJ_GEN.R002C0PAV21
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
EmsisoftTrojan.GenericKD.36276916 (B)
IkarusTrojan-Downloader.Win32.Generic
MAXmalware (ai score=87)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2298AB4
GDataWin32.Trojan-Downloader.Generic.IOOCZV
CynetMalicious (score: 90)
McAfeeArtemis!9AED5C0BEC3C
MalwarebytesMalware.Heuristic.1003
ESET-NOD32Win32/TrojanDownloader.Agent.FMZ
TrendMicro-HouseCallTROJ_GEN.R002H0CAU21
YandexRiskware.ProcPatcher!FxoPOS6q/Ns
SentinelOneStatic AI – Suspicious PE
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZexaF.34804.cuW@aKinZRpi
AVGWin32:Trojan-gen

How to remove Win32/TrojanDownloader.Agent.FMZ?

Win32/TrojanDownloader.Agent.FMZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment