Trojan

About “PowerShell/TrojanDownloader.Agent.CJP” infection

Malware Removal

The PowerShell/TrojanDownloader.Agent.CJP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PowerShell/TrojanDownloader.Agent.CJP virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

Related domains:

soapstampingmachines.com
j5cool.xyz

How to determine PowerShell/TrojanDownloader.Agent.CJP?


File Info:

crc32: 03E852D5
md5: cb4903e3fa44287b0690413e5f56b793
name: cowr.exe
sha1: 5573abf5a69d6c57a02a5a53deba32fe34aafff7
sha256: bf39273f16e1989339d73bffe6bd6fc1a32c7d48679ae1921257110b80f04c7a
sha512: ea31e35a27a001bf456a2b25511fae5e583c0aa3de0403b8a7fb227775a6be751174fe1100914b3cc493be36ade69259195f9c77286d0230476ce826ccc5df95
ssdeep: 24576:IAHnh+eWsN3skA4RV1Hom2KXMmHaHPc5:Ph+ZkldoPK8YaHq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

PowerShell/TrojanDownloader.Agent.CJP also known as:

BkavW32.RopeticLTC.Trojan
DrWebTrojan.Siggen9.6429
MicroWorld-eScanTrojan.GenericKD.42289174
FireEyeGeneric.mg.cb4903e3fa44287b
McAfeeArtemis!CB4903E3FA44
AegisLabTrojan.Win32.Mokes.m!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42289174
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTrojan.Win32.MALREP.THABEBO
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42289174
KasperskyBackdoor.Win32.Mokes.ahxp
AlibabaBackdoor:Win32/Mokes.656e1253
TencentWin32.Backdoor.Mokes.Szbl
Ad-AwareTrojan.GenericKD.42289174
EmsisoftTrojan.GenericKD.42289174 (B)
F-SecureHeuristic.HEUR/AGEN.1044801
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
SophosMal/Generic-S
CyrenW32/Trojan.GGBA-5043
AviraHEUR/AGEN.1044801
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2854816
ZoneAlarmBackdoor.Win32.Mokes.ahxp
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Downloader/Win32.AutoIt.C3973316
Acronissuspicious
VBA32Backdoor.Mokes
ALYacTrojan.GenericKD.42289174
MAXmalware (ai score=84)
MalwarebytesTrojan.Downloader.AutoIt
PandaTrj/CI.A
ESET-NOD32PowerShell/TrojanDownloader.Agent.CJP
TrendMicro-HouseCallTrojan.Win32.MALREP.THABEBO
eGambitUnsafe.AI_Score_77%
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
Cybereasonmalicious.5a69d6
AvastWin32:Trojan-gen
Qihoo-360Generic/HEUR/QVM10.2.CACD.Malware.Gen

How to remove PowerShell/TrojanDownloader.Agent.CJP?

PowerShell/TrojanDownloader.Agent.CJP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment