Malware

Troj/DwnLdr-ZFA malicious file

Malware Removal

The Troj/DwnLdr-ZFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DwnLdr-ZFA virus can do?

  • Network activity detected but not expressed in API logs

How to determine Troj/DwnLdr-ZFA?


File Info:

crc32: B3ADF8DF
md5: 661d5f6f42fda70bcfd1c8528796a215
name: jd.exe
sha1: c1011d12b4c8d4865f6fc4c1d3f2107d80b50a94
sha256: 97d51b94e0ea53eb995cd5f6dc03fd56dd318191ad4c02ae6299c17264f08c0b
sha512: 9ac2c6a4992a0f56c224dfe07c13faf83d5eaa58de6d37dcdb886bb268efeb3351f0c21a646fef1900ecc8c6f415d685946ec5cc86ed83d81d7eb91d2f284342
ssdeep: 6144:CfUbr0eQBLL/nA/XjO7K5515PuVk1uIIblB5LCACiSKA8e1h:+Ubr0eqL4zr11ezLCAbVAz7
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 1.0.0.0
InternalName: 1209876.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: 1209876.exe

Troj/DwnLdr-ZFA also known as:

MicroWorld-eScanGen:Variant.Razy.590325
McAfeeGenericRXJH-HP!661D5F6F42FD
CylanceUnsafe
AegisLabTrojan.Win32.Generic.m7QV
SangforMalware
K7AntiVirusTrojan ( 005302041 )
BitDefenderGen:Variant.Razy.590325
K7GWTrojan ( 005302041 )
Cybereasonmalicious.2b4c8d
Invinceaheuristic
CyrenW32/Trojan.BNYY-1777
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Generic.259efc3f
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.590325 (B)
F-SecureTrojan.TR/Kryptik.pmynw
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R023C0GLF19
McAfee-GW-EditionGenericRXJH-HP!661D5F6F42FD
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.661d5f6f42fda70b
SophosTroj/DwnLdr-ZFA
IkarusBackdoor.MSIL.Agent
GDataGen:Variant.Razy.590325
JiangminTrojan.Generic.ejuvt
WebrootW32.Trojan.Emotet
AviraTR/Kryptik.pmynw
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Razy.D901F5
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.RL_Agent.C3443135
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Razy.590325
Ad-AwareGen:Variant.Razy.590325
MalwarebytesTrojan.Crypt.MSIL.Generic
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.FWF
TrendMicro-HouseCallTROJ_GEN.R023C0GLF19
YandexTrojan.Agent!VB5JsBSKJo8
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic!tr
BitDefenderThetaGen:NN.ZemsilF.33556.qm0@a4gHKjk
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM03.0.D8C7.Malware.Gen

How to remove Troj/DwnLdr-ZFA?

Troj/DwnLdr-ZFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment