Downloader.Win32.Agent.mjba removal tips

Malware Removal

The Downloader.Win32.Agent.mjba is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Review

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Downloader.Win32.Agent.mjba virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

z.whorecord.xyz
a.tomx.xyz
w.nanweng.cn

How to determine Downloader.Win32.Agent.mjba?


File Info:

crc32: 347B52A1
md5: a95b04dba6369cc946adcdc5523584e6
name: lj1020-1022hbwin98me2kxp2003-sc82_136210.exe
sha1: cd1c20315fe6c20210922b708f92f1a881f9397e
sha256: 87bdcc54346055487e557df27f8c7d2bff1e8dcd39c47ec015ce3e9bb162b10f
sha512: 52b6ef4eab07565024eb1ace6a65bafa7a8f90f91944825a5a4d821d4b02682e8574e9763fa691b4698d9f491341a81230999dd21f7141d6cff1866a99738d40
ssdeep: 24576:awmwDGOjGg/vjBYqeJ2FSEkJ3mLwwrwKiWyksgd:afFOd5SVzHKfsgd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0528
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
FileDescription: _
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mjba also known as:

MicroWorld-eScanTrojan.GenericKD.34021776
FireEyeTrojan.GenericKD.34021776
McAfeeGenericRXAA-AA!A95B04DBA636
MalwarebytesAdware.ChinAd
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 005105151 )
BitDefenderTrojan.GenericKD.34021776
K7GWAdware ( 005105151 )
TrendMicroPUA.Win32.Qjwmonkey.HU
SymantecPUA.Gen.2
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
GDataTrojan.GenericKD.34021776
Kasperskynot-a-virus:Downloader.Win32.Agent.mjba
AlibabaDownloader:Win32/Qjwmonkey.be543ae2
NANO-AntivirusRiskware.Win32.Qjwmonkey.hlaspu
AegisLabRiskware.Win32.Agent.1!c
RisingAdware.Downloader!1.BDCA (CLOUD)
Endgamemalicious (high confidence)
EmsisoftApplication.Downloader (A)
ComodoApplicUnwnt@#d6j0vf2nvh87
F-SecureAdware.ADWARE/Qjwmonkey.zwtql
DrWebAdware.Qjwmonkey.168
ZillyaAdware.Qjwmonkey.Win32.656
SophosGeneric PUA MN (PUA)
CyrenW32/Trojan.VPNA-8610
JiangminDownloader.Agent.nhe
WebrootW32.Downloader.Gen
AviraADWARE/Qjwmonkey.zwtql
MAXmalware (ai score=99)
Antiy-AVLGrayWare/Win32.Qjwmonkey
ArcabitTrojan.Generic.D2072190
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mjba
MicrosoftPUA:Win32/Qjwmonkey
CynetMalicious (score: 85)
AhnLab-V3Adware/Win32.Qjwmonkey.R340429
VBA32BScope.TrojanDropper.Dapato
ALYacTrojan.GenericKD.34021776
Ad-AwareTrojan.GenericKD.34021776
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallPUA.Win32.Qjwmonkey.HU
TencentMalware.Win32.Gencirc.10cdd758
YandexPUA.Qjwmonkey!
eGambitTrojan.Generic
FortinetRiskware/Agent
AVGWin32:AdwareX-gen [Adw]

How to remove Downloader.Win32.Agent.mjba?

Downloader.Win32.Agent.mjba removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment