Malware

Java/Agent.JI information

Malware Removal

The Java/Agent.JI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Java/Agent.JI virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

java.com
www.bing.com

How to determine Java/Agent.JI?


File Info:

crc32: 8C09B1DF
md5: 14753bc4b3114d98a1cd9590cec5c6a8
name: 14753BC4B3114D98A1CD9590CEC5C6A8.mlw
sha1: 9337711714db214deda5b4d3edc09a423bb12ad4
sha256: 34bc2d9a96b0112df9fc8951a2f6692224278fbf01aca53bb7ec64ae50beeba0
sha512: bd136e3883c7ceaf5e5c99788dca2dad24f2ef5a4f11634d5d4551992ce6a4532ed6a8789139300e73032b073561768a3090d16666ef611bb0e5f8a6ec6b50e1
ssdeep: 384:78xXYSplN3+CYgjTiQD3nQJdNd/wrqnFLiiCp0M+McfKIYYr3a4jF3zj3zmKkm3t:4P7N3qgq0mNw2UiCp0MkfKAqQnGukBlE
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Java/Agent.JI also known as:

K7AntiVirusTrojan ( 00561d8f1 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.MulDrop11.49927
ALYacTrojan.GenericKD.42840703
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.58463
AlibabaTrojan:JAVA/Blocker.f7287f36
K7GWTrojan ( 00561d8f1 )
Cybereasonmalicious.4b3114
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Java/Agent.JI
AvastJava:Malware-gen [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.mnjg
BitDefenderTrojan.GenericKD.42840703
NANO-AntivirusTrojan.Win32.Blocker.hengba
MicroWorld-eScanTrojan.GenericKD.42840703
TencentWin32.Trojan.Blocker.Dxdd
Ad-AwareTrojan.GenericKD.42840703
ComodoMalware@#164dnznb2ayd6
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionJava/Agent.x!E0CC5C3DC911
FireEyeTrojan.GenericKD.42840703
EmsisoftTrojan.GenericKD.42840703 (B)
WebrootW32.Trojan.Gen
AviraEXP/JAVA.Banload.VPJ.Gen
MicrosoftTrojan:Win32/Occamy.C34
GDataTrojan.GenericKD.42840703
TACHYONRansom/W32.Blocker.33856
McAfeeArtemis!14753BC4B311
MAXmalware (ai score=83)
VBA32TrojanRansom.Blocker
PandaTrj/CI.A
IkarusTrojan.Java.Agent
MaxSecureTrojan.Malware.77434015.susgen
FortinetW32/Blocker.JI!tr
AVGJava:Malware-gen [Trj]
Paloaltogeneric.ml

How to remove Java/Agent.JI?

Java/Agent.JI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment