Trojan

What is “Trojan-Downloader.Win32.Paph.jjd”?

Malware Removal

The Trojan-Downloader.Win32.Paph.jjd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Paph.jjd virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A scripting utility was executed
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Paph.jjd?


File Info:

crc32: D263D6C3
md5: c568c38c058777f8ca5a6baa28a652a4
name: Server.jpg
sha1: 279e1411178f12b760bb8a387e1cf9f1c833c507
sha256: f426bccd4b1ff0a80a3ae9da9816eff29af07d2909a0a2691958bb5307aeb5f4
sha512: 9411adb9d896a8ae313bf46d67765efc479ba07f2a1fc96b85facea2a47cef106aa1a09e488b56391021a547ec36f4742e06849facb3260c8c3b631f1c9ff592
ssdeep: 1536:e7f++rgYVjYpunEipICdMkFhzxL+5/Q9wFkXomIOlnToIfyxOp:0Jg0eSGCikEGfXoENTBfyM
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Paph.jjd also known as:

DrWebTrojan.DownLoader29.9445
MicroWorld-eScanGen:Variant.Ursu.767855
FireEyeGeneric.mg.c568c38c058777f8
CAT-QuickHealTrojan.Wacatac
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ursu.767855
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c05877
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34098.fuW@ay!@hKh
F-ProtW32/Ursu.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ZonerTrojan.Win32.85523
TrendMicro-HouseCallTROJ_GRAFTOR_HB28001C.UVPM
GDataGen:Variant.Ursu.767855
KasperskyTrojan-Downloader.Win32.Paph.jjd
AlibabaTrojanDownloader:Win32/Generic.ff0cc151
NANO-AntivirusTrojan.Win32.Scrop.eyqkso
AegisLabTrojan.Win32.Ulise.4!c
RisingDownloader.Agent!8.B23 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ursu.767855 (B)
ZillyaDropper.Scrop.Win32.124
TrendMicroTROJ_GRAFTOR_HB28001C.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.PowerShell.Agent
CyrenW32/Ursu.AU.gen!Eldorado
JiangminTrojanDropper.Scrop.rp
MaxSecureTrojan.Malware.74483024.susgen
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ursu.DBB76F
ZoneAlarmTrojan-Downloader.Win32.Paph.jjd
AhnLab-V3Malware/Win32.Generic.C2407879
Acronissuspicious
VBA32Trojan.Script
MAXmalware (ai score=88)
Ad-AwareGen:Variant.Ursu.767855
PandaTrj/CI.A
APEXMalicious
ESET-NOD32PowerShell/TrojanDownloader.Agent.BFT
TencentMalware.Win32.Gencirc.10b6347b
eGambitUnsafe.AI_Score_93%
FortinetW32/GRAFTOR_HB28001C.UVPM!tr
WebrootW32.Adware.Gen
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Downloader.479

How to remove Trojan-Downloader.Win32.Paph.jjd?

Trojan-Downloader.Win32.Paph.jjd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment