Trojan

Trojan.Jenix.13329 information

Malware Removal

The Trojan.Jenix.13329 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Jenix.13329 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

www.baidu.com
www.soso.com
m.baidu.com

How to determine Trojan.Jenix.13329?


File Info:

crc32: 551AE116
md5: 418aa8aafc6f2137e134dbb6358d5968
name: dzsoft.exe
sha1: 6f1b0c45d4c039d9600ce8a4cfa158691de05b13
sha256: 1519597121d033d71dcb681701db36b8247c2f24d74c98b87210bf7ba91e1076
sha512: 200cfaf6a828c86d914acdc8da6773ff5413009366051a319f099fdf1864f1cfa4a4c2b09138c647fe90d2a8840d91d5d578aac3b935753865fff2470c4e1bdb
ssdeep: 49152:yrT5Xuv5SA2mljbctI+s8KuqGaX0ToIBAUZLY6qh:QToBH2mljbEbJBAUZLLqh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x672cx8f6fx4ef6x6700x7ec8x89e3x91cax6743x4e3ax5f69x65e0x654cx6240x6709 QQ1257251000
FileVersion: 1.0.0.0
CompanyName: www.cwdcp.com
Comments: x5f69x65e0x654cx6bb5x7ec4x5de5x5177
ProductName: x5f69x65e0x654cx6bb5x7ec4x5de5x5177
ProductVersion: 1.0.0.0
FileDescription: x5f69x65e0x654cx6bb5x7ec4x5de5x5177
Translation: 0x0804 0x04b0

Trojan.Jenix.13329 also known as:

K7AntiVirusTrojan ( 005246d51 )
MicroWorld-eScanTrojan.GenericKD.4778682
FireEyeGeneric.mg.418aa8aafc6f2137
CAT-QuickHealTrojan.Jenix.13329
McAfeeArtemis!418AA8AAFC6F
CylanceUnsafe
AlibabaPUA:Win32/FlyStudio.375e5334
K7GWTrojan ( 00013a151 )
ArcabitTrojan.Generic.D48EABA
F-ProtW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.4778682
Paloaltogeneric.ml
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.4778682 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
ZillyaWorm.FlyStudio.Win32.2433
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosGeneric PUA GP (PUA)
CyrenW32/Trojan.CLL.gen!Eldorado
Antiy-AVLGrayWare/Win32.FlyStudio.a
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Application.FlyStudio.F
Acronissuspicious
ALYacTrojan.GenericKD.4778682
MAXmalware (ai score=89)
Ad-AwareTrojan.GenericKD.4778682
ESET-NOD32a variant of Win32/FlyStudio.Injector.A potentially unwanted
RisingMalware.Undefined!8.C (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_64%
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Cybereasonmalicious.afc6f2
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Jenix.13329?

Trojan.Jenix.13329 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment