Malware

What is “Application.Agent.JFD”?

Malware Removal

The Application.Agent.JFD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.JFD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Application.Agent.JFD?


File Info:

name: 9D029101F142D6105B30.mlw
path: /opt/CAPEv2/storage/binaries/eadc3c15ff271edeb782c876db1ccf42d936fb7419bd271beac2e9d9bef67a7e
crc32: 61695BD8
md5: 9d029101f142d6105b30b76666ae4565
sha1: 1df15fa5255a268bab58c087612f2b873761e72c
sha256: eadc3c15ff271edeb782c876db1ccf42d936fb7419bd271beac2e9d9bef67a7e
sha512: e74610b673206ae219484998d64cd883153180bd0577cbcb1c241a589fcac53cb08803514fe21385d65cc86f39a9cdb3d2392b9e4be86b27c1beb0f895dffb3e
ssdeep: 196608:RlkFQmYQij4Lef9KYhJfMnMLVtlBNa1SRGly0RB9vMTZLazT6:4F1g9K0SMPZXqmNLaz2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129A63305EB40317AC861DA7A81104098293FACCD6EAC6747334EED616F67F93158DBAF
sha3_384: 824c03cb38570bb4309754ad3af20e4c7341ee889165faa8a38a2597720578a4575e2f20631e094abe4df6c999474e71
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2020-08-29 23:10:29

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Piston Software
FileDescription: WAV MP3 Splitter Setup
FileVersion:
LegalCopyright:
ProductName: WAV MP3 Splitter
ProductVersion: 0.6.1.2
Translation: 0x0000 0x04b0

Application.Agent.JFD also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Agent.JFD
FireEyeApplication.Agent.JFD
McAfeeArtemis!9D029101F142
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 0056c5d31 )
BitDefenderApplication.Agent.JFD
K7GWTrojan-Downloader ( 0056c5d31 )
Cybereasonmalicious.1f142d
CyrenW32/DownloadAssist.P.gen!Eldorado
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.afedd
AlibabaTrojan:Win32/Ekstak.0c4f50a3
Ad-AwareApplication.Agent.JFD
SophosMal/Generic-R + Troj/Agent-BFJN
ComodoMalware@#18q1i7iwywsx6
DrWebTrojan.DownLoader34.29677
ZillyaTrojan.Ekstak.Win32.54152
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
EmsisoftApplication.Downloader (A)
IkarusTrojan-Downloader.Zurgop
JiangminTrojan.Ekstak.bjik
AviraHEUR/AGEN.1138873
MAXmalware (ai score=72)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataApplication.Agent.JFD
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.DownloadAssistant.R349899
ALYacApplication.Agent.JFD
MalwarebytesTrojan.Downloader.Generic
TencentWin32.Trojan.Ekstak.Htlq
YandexTrojan.DL.Zurgop!7dp85ZJ4E3Q
SentinelOneStatic AI – Suspicious PE
FortinetW32/Zurgop.DJ!tr
AVGWin32:AdwareX-gen [Adw]
AvastWin32:AdwareX-gen [Adw]

How to remove Application.Agent.JFD?

Application.Agent.JFD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment