Trojan

About “Trojan.Downloader.JPAN” infection

Malware Removal

The Trojan.Downloader.JPAN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.JPAN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Downloader.JPAN?


File Info:

name: B7221AC5AE0683FAA981.mlw
path: /opt/CAPEv2/storage/binaries/373efdffda6c17c803cba64a17f13d6e9cd12bdc95d71d1f02c5c757b17d0a13
crc32: 0DC2C23C
md5: b7221ac5ae0683faa981049518fa82d3
sha1: 09e2703cc7ad80bd0fc846b2cd6dc25cbbff39c4
sha256: 373efdffda6c17c803cba64a17f13d6e9cd12bdc95d71d1f02c5c757b17d0a13
sha512: 10359503fe396f9fba7da99d4d862f6a38bf93f857588b75a3c9557a99621ca5d2e325d4972b01ed0b2715aea2f8e0ba27484f0f92468e2f4c41179e743bbed1
ssdeep: 3072:hLO3n0qFEj+5aQNAKllzZP3XUjolCiQVqZjhnIf5O+xkqC1S3HVoD4VkHAvrulr:an0nwZMclCiQVqZjhnIf5O+xkqC1mHVs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E704D57DB390973EE416E2F6696A8398106D6E3A28D1E417F7C22B08B5F09E3D131353
sha3_384: 6465eee0685b0be114deb594275c98c56ccd75e8ad0c3d75ac738c703f3eb9137482f3e6cf184d726a3104acaea16d99
ep_bytes: 6874394000e8f0ffffff000000000000
timestamp: 2012-01-25 19:13:30

Version Info:

Translation: 0x0409 0x04b0
ProductName: HMhcgcebB
FileVersion: 1.00
ProductVersion: 1.00
InternalName: vdfKSXbt
OriginalFilename: vdfKSXbt.exe

Trojan.Downloader.JPAN also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.ltc8
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.b7221ac5ae0683fa
CAT-QuickHealTrojan.JorikVMF.S19739448
ALYacTrojan.Downloader.JPAN
MalwarebytesWorm.Obfuscator
ZillyaTrojan.Jorik.Win32.1016909
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ffc.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.5ae068
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Zyx.HP
CyrenW32/Vobfus.AI.gen!Eldorado
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AQZ
APEXMalicious
ClamAVWin.Trojan.Vobfus-42
KasperskyTrojan.Win32.Jorik.Vobfus.gtpg
BitDefenderTrojan.Downloader.JPAN
NANO-AntivirusTrojan.Win32.WBNA.chvyyl
SUPERAntiSpywareTrojan.Agent/Gen-Remnat[VB]
MicroWorld-eScanTrojan.Downloader.JPAN
AvastWin32:AutoRun-COV [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.Jorik.184464
SophosMal/VBCheMan-B
F-SecureTrojan.TR/Otran.ammnb
DrWebTrojan.VbCrypt.60
VIPRETrojan.Downloader.JPAN
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
EmsisoftTrojan.Downloader.JPAN (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Downloader.JPAN
JiangminWorm/WBNA.eucu
AviraTR/Otran.ammnb
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Downloader.JPAN
ViRobotTrojan.Win32.A.VBKrypt.184320.CD
ZoneAlarmTrojan.Win32.Jorik.Vobfus.gtpg
MicrosoftWorm:Win32/Vobfus.gen!P
GoogleDetected
AhnLab-V3Trojan/Win.VBKrypt.R557016
McAfeeVBObfus.cu
MAXmalware (ai score=83)
VBA32BScope.Trojan.VBCR.2512
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!p5p9FWs+0AI
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.11625478.susgen
FortinetW32/VBObfus.CM!tr
BitDefenderThetaGen:NN.ZevbaF.36250.lm1@aKMtHXdi
AVGWin32:AutoRun-COV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Downloader.JPAN?

Trojan.Downloader.JPAN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment