Trojan

Trojan.Downloader.JRZZ removal guide

Malware Removal

The Trojan.Downloader.JRZZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.JRZZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Mimics icon used for popular non-executable file format

How to determine Trojan.Downloader.JRZZ?


File Info:

name: 79DD7652F207D939FC24.mlw
path: /opt/CAPEv2/storage/binaries/0a349b56b15488440d22576641d1cfd5a232906589d9535d73fd02dce5592ea1
crc32: 00924744
md5: 79dd7652f207d939fc243aa247b1d465
sha1: 55a6901ed0419874fcecf88a66ea62c78aaff7a1
sha256: 0a349b56b15488440d22576641d1cfd5a232906589d9535d73fd02dce5592ea1
sha512: fc18a164698cb6d3fc07167e31b98476b24c8ffe0b8c574745043bcd8a0cc11639642944ae462de34a1f5a599da2af5b6b5af3b4d4554b735f030ea47f58f2ab
ssdeep: 768:dD2BxbvDdE6+bIpS4jTjZJwyOFciB9l3jifVMhJobJNiXjPGGIIwQqQNR69o3sym:dD2BobiS4jHHNOedAobJNErGGwL9oPm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D6D37E366DE0C5B6F3B78AB454F15ACE6B3AFD165E06194F81D006872C33AE29C3161B
sha3_384: b888bf25a28f420b46c71fa9cd032e7235e1e6f555925d95808e5afa3c40442a2430ab3ee9ca679a5b028586f8d724fc
ep_bytes: 558bec6aff68f8b5400068ac37400064
timestamp: 2015-07-22 08:27:16

Version Info:

BuildVersion: 7, 15, 22, 129
Translation: 0x0419 0x04b0

Trojan.Downloader.JRZZ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.JRZZ
FireEyeGeneric.mg.79dd7652f207d939
CAT-QuickHealTrojanDownloader.Upatre.RF4
McAfeeDownloader-FAWW!79DD7652F207
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.764883
K7AntiVirusTrojan ( 004c92211 )
K7GWTrojan ( 004c92211 )
CrowdStrikewin/malicious_confidence_90% (D)
BaiduWin32.Trojan.Kryptik.ks
CyrenW32/Trojan.JNBU-7452
SymantecDownloader.Upatre
ESET-NOD32a variant of Win32/Kryptik.DQYD
APEXMalicious
ClamAVWin.Downloader.Upatre-7374321-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JRZZ
NANO-AntivirusTrojan.Win32.Dwn.duhhfu
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
AvastWin32:Crypt-SDI [Trj]
RisingDownloader.Upatre!1.A19D (CLASSIC)
Ad-AwareTrojan.Downloader.JRZZ
SophosML/PE-A + Mal/Vawtrak-S
ComodoTrojWare.Win32.TrojanDownloader.Upatre.DLF@5t0aja
DrWebTrojan.DownLoader15.6021
VIPRETrojan-Downloader.Win32.Waski.mf (v)
TrendMicroTROJ_UPATRE.SMJTU
McAfee-GW-EditionBehavesLike.Win32.Downloader.cz
EmsisoftTrojan.Downloader.JRZZ (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Downloader.JRZZ
JiangminTrojan/Generic.bhigq
eGambitUnsafe.AI_Score_99%
AviraTR/Kryptik.abbogp
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.130D5F9
ViRobotTrojan.Win32.Upatre.135168.A
MicrosoftTrojanDownloader:Win32/Upatre
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R159433
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.iqX@aKKf2Cac
ALYacTrojan.Downloader.JRZZ
VBA32BScope.Malware-Cryptor.Dyllu
MalwarebytesMalware.AI.1232219269
TrendMicro-HouseCallTROJ_UPATRE.SMJTU
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!8D+PFuOKM1c
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.DRBQ!tr
AVGWin32:Crypt-SDI [Trj]
Cybereasonmalicious.2f207d
PandaTrj/Genetic.gen

How to remove Trojan.Downloader.JRZZ?

Trojan.Downloader.JRZZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment