Malware

About “Downloader.Win32.Agent.mjht” infection

Malware Removal

The Downloader.Win32.Agent.mjht is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mjht virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (14 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
w.nanweng.cn
www.msn.com
static-global-s-msn-com.akamaized.net
web.vortex.data.msn.com
ocsp.digicert.com
ocsp.msocsp.com
img-s-msn-com.akamaized.net

How to determine Downloader.Win32.Agent.mjht?


File Info:

crc32: 93EA0434
md5: d728abd6e97793a989f65243dc7e5538
name: zoom-E794B5E88491E789881808_123762.exe
sha1: e785f9e901080ed3acefac105d9a1977aad1f6dc
sha256: d0239a266ffa2a3221cc473d36e62a71403184199b8198262e016fec46476239
sha512: 913ad7de3ed0fc62325657b9831fe97f8ed3a0e562e3d6e82c98867b9a7fc1b1d3f677dc2cfa24aa0a0e97477741fb9d0654d1aa9ffdf6c322530ea55dbedd28
ssdeep: 24576:1PFwAnd6PHY7y1KeLgFKkDhd+Rvo3IQNYG9Ojps5d:KPY+yiOd9ks5d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0619
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
FileDescription: _
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mjht also known as:

MicroWorld-eScanGen:Variant.Adware.Zusy.189946
FireEyeGen:Variant.Adware.Zusy.189946
McAfeeGenericRXAA-AA!D728ABD6E977
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005694e51 )
BitDefenderGen:Variant.Adware.Zusy.189946
K7GWAdware ( 00510c5c1 )
TrendMicroTrojan.Win32.WACATAC.USXVPG220
SymantecPUA.Gen.2
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
GDataGen:Variant.Adware.Zusy.189946
Kasperskynot-a-virus:Downloader.Win32.Agent.mjht
AlibabaDownloader:Win32/Qjwmonkey.12f30f58
NANO-AntivirusRiskware.Win32.Qjwmonkey.hmohro
RisingAdware.Qjwmonkey!8.18F (CLOUD)
Endgamemalicious (high confidence)
EmsisoftApplication.Downloader (A)
F-SecureAdware.ADWARE/Qjwmonkey.ygcuy
DrWebAdware.Qjwmonkey.168
MaxSecureTrojan.Malware.121218.susgen
SophosGeneric PUA OH (PUA)
CyrenW32/Adware.GVGY-6589
JiangminDownloader.Agent.noz
WebrootW32.Adware.Gen
AviraADWARE/Qjwmonkey.ygcuy
Antiy-AVLRiskWare[Downloader]/Win32.Agent
MicrosoftPUA:Win32/Qjwmonkey
ArcabitTrojan.Adware.Zusy.D2E5FA
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mjht
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.Qjwmonkey.C4156179
ALYacGen:Variant.Adware.Zusy.189946
MAXmalware (ai score=63)
VBA32BScope.TrojanDropper.Dapato
MalwarebytesAdware.ChinAd
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTrojan.Win32.WACATAC.USXVPG220
TencentMalware.Win32.Gencirc.119f9214
eGambitTrojan.Generic
FortinetRiskware/Agent
Ad-AwareGen:Variant.Adware.Zusy.189946
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Downloader.Win32.Agent.mjht?

Downloader.Win32.Agent.mjht removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment