Trojan

Java/TrojanDownloader.Agent.NWR.Gen malicious file

Malware Removal

The Java/TrojanDownloader.Agent.NWR.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Java/TrojanDownloader.Agent.NWR.Gen virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Java/TrojanDownloader.Agent.NWR.Gen?


File Info:

name: EB34088790AB207CBD21.mlw
path: /opt/CAPEv2/storage/binaries/f3079d6a98eaa05edc5cc71f11177ad47f5263056bd545dd488b9fa8deae9e63
crc32: 86C829E6
md5: eb34088790ab207cbd21c9c34f1ef74e
sha1: 90d220cdeccc6b6674a19901ae77cd492eb4b160
sha256: f3079d6a98eaa05edc5cc71f11177ad47f5263056bd545dd488b9fa8deae9e63
sha512: 1c8a40bddfb609ee4e345a33ca953534ac85f423f66b2ee065d5da63605b20d4b7712a93c4933f1b1fb9952b12bd5c7e2d20686419996e089c406a54a237e95e
ssdeep: 98304:L04TdxUpQ7AcZFSlTBrHJWGs2NyqeoNE/7SRYY2VymGu/m6zHAlA64TRRbCvp:L04IjcZElTVHJack+YlGlSRRbCvp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA760173F0DA1471F8732A36B8925472393E089CE08729A929B4ABD7F572D4C4F4B791
sha3_384: 70da338111d15eb3c382ffdf833b9242ad1c18421d221ae5c714a20fb43fb28414ba306b723b47a2bbbb7ad747513e58
ep_bytes: 5589e583ec08c7042402000000ff1590
timestamp: 2023-08-17 15:25:48

Version Info:

CompanyName: Twilio
FileDescription: Product Analytics for the Digital Era
FileVersion: 20.16.15.3
InternalName: WhenDatabase.exe
Copyright: All reserved
OriginalFilename: WhenDatabase.exe
ProductName: Keyboard Training
ProductVersion: 20.16.15.3
Translation: 0x0409 0x04e4

Java/TrojanDownloader.Agent.NWR.Gen also known as:

BkavW32.Common.3210BECE
MicroWorld-eScanTrojan.GenericKD.68947126
FireEyeTrojan.GenericKD.68947126
ALYacTrojan.GenericKD.68947126
Cylanceunsafe
ZillyaTrojan.Cobalt.Win32.3132
ArcabitTrojan.Generic.D41C0CB6
CyrenW32/ABRisk.SCTR-8107
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32Java/TrojanDownloader.Agent.NWR.Gen
KasperskyTrojan.Win32.Cobalt.rdo
BitDefenderTrojan.GenericKD.68947126
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13ecd68e
F-SecureTrojan.TR/Cobalt.jziii
VIPRETrojan.GenericKD.68947126
TrendMicroTrojanSpy.Win32.STEALC.YXDHVZ
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.68947126 (B)
AviraTR/Cobalt.jziii
ZoneAlarmTrojan.Win32.Cobalt.rdo
GDataTrojan.GenericKD.68947126
GoogleDetected
McAfeeArtemis!EB34088790AB
MAXmalware (ai score=85)
MalwarebytesSpyware.Stealer
TrendMicro-HouseCallTrojanSpy.Win32.STEALC.YXDHVZ
MaxSecureTrojan.Malware.216127432.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Java/TrojanDownloader.Agent.NWR.Gen?

Java/TrojanDownloader.Agent.NWR.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment