Trojan

Trojan.ExplorerHijack.WiGeaOA!Jmii malicious file

Malware Removal

The Trojan.ExplorerHijack.WiGeaOA!Jmii is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ExplorerHijack.WiGeaOA!Jmii virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • Starts servers listening on 127.0.0.1:54323
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk

Related domains:

aol.playbatllesgrounds.com

How to determine Trojan.ExplorerHijack.WiGeaOA!Jmii?


File Info:

crc32: 73A3E694
md5: ffa8fefa25374a49d2eb68ba597c98f6
name: ffa8fefa25374a49d2eb68ba597c98f6.exe
sha1: b2579e9783a47e53b3ec0ed58410ab938775def2
sha256: 1019c65e382d68b5cfaae3d112cbeb051a114486ca26cc23df20e0adf1ce673c
sha512: 92dca5577fd7c0ac88da7cdbfdc03b953aa76dd205e45393ccb3dd3770e10be11ed612cb07336978dc16e0fa08a022dcffa365ddb69ac298f9afad3222a40163
ssdeep: 12288:YhWfr2iao7ENjOhMeIihBIH+Fqmeo0pfnQ26eomrdPhobCFa213UJl:tSno7EVOCAy620EObCFJhUJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.ExplorerHijack.WiGeaOA!Jmii also known as:

DrWebTrojan.Siggen9.2810
MicroWorld-eScanGen:Trojan.ExplorerHijack.WiGeaOA!Jmii
FireEyeGeneric.mg.ffa8fefa25374a49
CAT-QuickHealTrojan.Generic
ALYacGen:Trojan.ExplorerHijack.WiGeaOA!Jmii
SangforMalware
K7AntiVirusTrojan ( 005329b91 )
BitDefenderGen:Trojan.ExplorerHijack.WiGeaOA!Jmii
K7GWTrojan ( 005329b91 )
Cybereasonmalicious.a25374
TrendMicroCryp_Xed-12
BitDefenderThetaAI:Packer.B561A53724
TrendMicro-HouseCallCryp_Xed-12
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDropper:Win32/dropper.ali1003001
NANO-AntivirusTrojan.Win32.OnLineGames.grgbex
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Trojan.ExplorerHijack.WiGeaOA!Jmii
SophosMal/EncPk-BW
ComodoPacked.Win32.Klone.~KMG@1knj1d
F-SecureTrojan.TR/Downloader.Gen
VIPREPacked.Win32.Upack (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bc
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ExplorerHijack.WiGeaOA!Jmii (B)
IkarusTrojan-PSW.OnlineGames
GDataGen:Trojan.ExplorerHijack.WiGeaOA!Jmii
JiangminTrojan.Generic.dzgpr
AviraTR/Downloader.Gen
MicrosoftTrojan:Win32/OnLineGameHijack!ibt
Endgamemalicious (high confidence)
ArcabitTrojan.ExplorerHijack.WiGeaOA!Jmii
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Packed/Upack
Acronissuspicious
McAfeeArtemis!FFA8FEFA2537
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
APEXMalicious
ESET-NOD32a variant of Win32/PSW.OnLineGames.QZO
RisingStealer.OnLineGames!8.131 (CLOUD)
YandexTrojan.Agent!oUNOBO7hDDo
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Onlinegames.QZO!tr
Qihoo-360Win32/Trojan.49e
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.ExplorerHijack.WiGeaOA!Jmii?

Trojan.ExplorerHijack.WiGeaOA!Jmii removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment