Malware

What is “Downloader.Win32.Agent.mjzj”?

Malware Removal

The Downloader.Win32.Agent.mjzj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mjzj virus can do?

  • Presents an Authenticode digital signature
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

z.whorecord.xyz
a.tomx.xyz
downloader.aldtop.com
www.pc6.com
resource.aldtop.com
img.aldtop.com

How to determine Downloader.Win32.Agent.mjzj?


File Info:

crc32: 02EBC3C8
md5: 1073f6285820c0783c6ae42907ed7a15
name: vc2005_03856323.exe
sha1: 6282c21574ea6fa19c8bbaf95cf67a6df6ddfd43
sha256: 27300dcc87f79d9046c2fe01bd2fb271ba049c0c2e616962c0abdddc5d99c44d
sha512: fc47c1584c209b7309c7f3414d9043a0894f1db28fc9989a73c2387950074f920324bf7f7e130150ae9dde3b48ba7f9dc92d02e835a922b1cb86ec8d723e7d38
ssdeep: 24576:dsKuGWFgHxOtXFhjxzjEhfe/49AOsnTbN3lOmFwraHmK1biuOd7:eKuGWFa8FbHEY/AjuTbPOPr0X1pOd7
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: FastDownloader.exe
FileVersion: 3.2.0.8
CompanyName: -
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.2.0.8
FileDescription:
OriginalFilename: FastDownloader.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mjzj also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Bundler.313
FireEyeGeneric.mg.1073f6285820c078
McAfeeArtemis!1073F6285820
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0054404d1 )
BitDefenderGen:Variant.Application.Bundler.313
K7GWRiskware ( 0054404d1 )
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:Downloader.Win32.Agent.mjzj
AlibabaDownloader:Win32/Downer.bd6ba993
ViRobotAdware.Downer.1134088.B
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Application.Bundler.313
F-SecureHeuristic.HEUR/AGEN.1126112
DrWebAdware.Downware.19825
Invinceaheuristic
SophosGeneric PUA GC (PUA)
IkarusPUA.RiskWare.Downer
CyrenW32/Application.DDAA-7422
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1126112
FortinetRiskware/Agent
ArcabitTrojan.Application.Bundler.313
MicrosoftPUA:Win32/Hypnamer.C!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Downloader.R345401
MAXmalware (ai score=77)
MalwarebytesPUP.Optional.FastDownloader
ESET-NOD32a variant of Win32/RiskWare.Downer.B
TrendMicro-HouseCallTROJ_GEN.R002H0CHD20
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Application.Bundler.313
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove Downloader.Win32.Agent.mjzj?

Downloader.Win32.Agent.mjzj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment