Trojan

Trojan.Downloader.JRZV removal tips

Malware Removal

The Trojan.Downloader.JRZV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.JRZV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (144 unique times)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Kelihos malware
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP

How to determine Trojan.Downloader.JRZV?


File Info:

name: ECF2A3FAAE0725C210BF.mlw
path: /opt/CAPEv2/storage/binaries/52631b92d34a243292e3fa5000c1cdea901461e0be3a46266199d067a0240ed2
crc32: 7AC45F8F
md5: ecf2a3faae0725c210bfcbd96d9a59e0
sha1: b10f1cfd76212fcb54724dd603417c1088fb4630
sha256: 52631b92d34a243292e3fa5000c1cdea901461e0be3a46266199d067a0240ed2
sha512: 9e69e70ca460b14ed7b85a53b15bedd514a28275d8c816a53e52bc404fe19e30c4d7e873c24ea6d4ef003031a92de5948d4a35dc8a1bf50b01330aa10d7fbde0
ssdeep: 24576:F/PJ6SX9z60Qq8j5Clqi5wgjvFVUpXcuszrzudxMRuboqASWMe+FK4kyNIU:F3vX9O0Qq8Aj5R7UpRszfmMUo1SWdDy3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0253301EB752A2DF2040670579713FA21A874B12E4398FA3C57AFBE0472715FE97D2A
sha3_384: ee3460e4ee0ec932368f74f87e9e869a2280b2be87310199ec5b4a2ce2d21d7993f68dc91a264c0cab40c8f16a591ff4
ep_bytes: 558bec6aff68d026400068a21d400064
timestamp: 2015-07-07 18:27:33

Version Info:

0: [No Data]

Trojan.Downloader.JRZV also known as:

LionicTrojan.Win32.Agent.mC6T
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.1383
MicroWorld-eScanTrojan.Downloader.JRZV
FireEyeGeneric.mg.ecf2a3faae0725c2
CAT-QuickHealTrojanPWS.Zbot.A4
McAfeePacked-FB!ECF2A3FAAE07
CylanceUnsafe
ZillyaTrojan.Agent.Win32.557474
SangforTrojan.Win32.Senta.8
K7AntiVirusTrojan ( 004c7e1e1 )
AlibabaTrojan:Win32/Dorv.f87ff035
K7GWTrojan ( 004c7e1e1 )
Cybereasonmalicious.aae072
BitDefenderThetaGen:NN.ZexaF.34182.arZ@aGYKvVe
VirITTrojan.Win32.Inject2.CNOA
CyrenW32/S-1bc9580e!Eldorado
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Injector.CFHM
TrendMicro-HouseCallBKDR_KELIHOS.SMNA
Paloaltogeneric.ml
ClamAVWin.Malware.Blkx-6951312-0
KasperskyTrojan.Win32.Agent.ifuz
BitDefenderTrojan.Downloader.JRZV
NANO-AntivirusTrojan.Win32.Encoder.dufbcp
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
AvastSf:Agent-BA [Trj]
TencentMalware.Win32.Gencirc.10b715d4
EmsisoftTrojan.Downloader.JRZV (B)
ComodoTrojWare.Win32.VirTool.CeeInject.KGR@5t0fp3
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_KELIHOS.SMNA
McAfee-GW-EditionBehavesLike.Win32.VirRansom.tc
SophosML/PE-A + Mal/Zbot-UE
JiangminTrojan/Agent.ijuv
WebrootW32.Trojan.Gen
AviraTR/Inject.sbbeinx
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.12C0D62
KingsoftWin32.Troj.Agent.if.(kcloud)
MicrosoftTrojan:Win32/DllCheck.A!MSR
ZoneAlarmTrojan.Win32.Agent.ifuz
GDataTrojan.Downloader.JRZV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CTBLocker.R158760
VBA32OScope.Malware-Cryptor.Hlux
ALYacTrojan.Downloader.JRZV
MalwarebytesMalware.AI.798183777
APEXMalicious
RisingTrojan.Senta!8.66F (CLOUD)
YandexTrojan.Agent!cLGKh7AQdGo
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Injector.CFFW!tr
AVGSf:Agent-BA [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Downloader.JRZV?

Trojan.Downloader.JRZV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment