Trojan

Trojan.Agent.CZJW malicious file

Malware Removal

The Trojan.Agent.CZJW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CZJW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Trojan.Agent.CZJW?


File Info:

crc32: B0A5E2E7
md5: e0d5192e5c1b181a3591ebbeebd9011d
name: E0D5192E5C1B181A3591EBBEEBD9011D.mlw
sha1: 39018344d1ccc10257a9d27e03719063b584b0c5
sha256: 4f94fe3da061c38781c4fad963d74c2de0125c826cbc2321e16c0b1536d9e566
sha512: 2346e566229dfbd879e500f40dc1875f029c2bbb27a57af2e90d53f16765b8599d55fef0daa89139a453d72b5ead3e6e14d6c788f03bd03d9077251589a3ec8b
ssdeep: 3072:KbnGS39iKR1Bd5VQZvJtd9IMAIKJTRvL2Ag0FubXyGPf5gvUVSXy9qs3MA2EE0N8:KbTiKTF0/IBIlAOPW88XBERk35xU7HhS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.CZJW also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Packed.Gandcrab-6552923-4
FireEyeGeneric.mg.e0d5192e5c1b181a
CAT-QuickHealTrojan.Cloxer.A06
Qihoo-360Win32/Trojan.f9e
McAfeeTrojan-FPQB!E0D5192E5C1B
CylanceUnsafe
ZillyaBackdoor.Mokes.Win32.1202
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 0053305e1 )
BitDefenderTrojan.Agent.CZJW
K7GWTrojan ( 005328b91 )
Cybereasonmalicious.e5c1b1
CyrenW32/S-97c363a1!Eldorado
SymantecPacked.Generic.525
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Panda.fcmesv
ViRobotTrojan.Win32.GandCrab.Gen.A
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.Agent.CZJW
RisingTrojan.Kryptik!1.B28B (RDMK:cmRtazqyWa7I8wM5G3RPfFWHGcc0)
Ad-AwareTrojan.Agent.CZJW
SophosMal/Generic-S + Mal/Agent-AUL
ComodoTrojWare.Win32.Magniber.FGH@7nyazg
F-SecureTrojan.TR/AD.GandCrab.fsmec
DrWebTrojan.PWS.Panda.13454
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_GANDCRAB.SMD4
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftTrojan.Agent.CZJW (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.GandCrab.fsmec
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Chapak
MicrosoftRansom:Win32/Gandcrab.D!MTB
ArcabitTrojan.Agent.CZJW
AegisLabTrojan.Win32.GandCrypt.j!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Agent.CZJW
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.tyX@aaftjhk
ALYacTrojan.Agent.CZJW
TACHYONRansom/W32.GandCrab
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GGZI
TrendMicro-HouseCallRansom_GANDCRAB.SMD4
TencentMalware.Win32.Gencirc.114b37ad
YandexTrojan.GenAsa!3FEGGstBgys
IkarusTrojan-Ransom.GandCrab
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.DQHN!tr
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureRansomeware.GandCrypt.Gen

How to remove Trojan.Agent.CZJW?

Trojan.Agent.CZJW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment