Trojan

Trojan.Win32.Cossta.ajjf removal instruction

Malware Removal

The Trojan.Win32.Cossta.ajjf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cossta.ajjf virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs Tor on the infected machine
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
artist.ba
www.aviafilm.com.ua
www.yahoo.com
www.globo.com
www.msn.com
www.terra.com.br
ocsp.pki.goog
www.ip-adress.com
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
r3.o.lencr.org

How to determine Trojan.Win32.Cossta.ajjf?


File Info:

crc32: 2AD9D228
md5: 0512969b9150edb637ea1bdb95dd1e66
name: 0512969B9150EDB637EA1BDB95DD1E66.mlw
sha1: d555e6938a5b23759645d0823d3ae36dde0f49c9
sha256: b0821abaad49bbe9a37fa0803e9a3978d30613c8259d4cdc9b27fbc5bfcbb2bb
sha512: f4dd668dd871311534170a1712e128d8b179f4296ec6975896fc1a88511841319dccb8f8cf59d4c0c8b5c7b56ca32935d6ff03d24a86b72b83429da9ae0f16c2
ssdeep: 24576:yoimtfCdeL769/M3zKF/hDGUv6dDx3SzI0ClvsmhiZoXmZ:HimtO9nhtOlvJimi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: a
FileVersion: 1.00
CompanyName: nvyotz
ProductName: roqqxx
ProductVersion: 1.00
OriginalFilename: a.exe

Trojan.Win32.Cossta.ajjf also known as:

BkavW32.AIDetect.malware2
K7AntiVirusNetWorm ( 700000151 )
Elasticmalicious (high confidence)
DrWebBACKDOOR.Trojan
CynetMalicious (score: 99)
ALYacGen:Heur.PonyStealer.MLT.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.b9150e
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Spy.Bancos.AAO
APEXMalicious
AvastWin32:GenMalicious-XO [Trj]
ClamAVWin.Trojan.Dialog-9873788-0
KasperskyTrojan.Win32.Cossta.ajjf
BitDefenderGen:Heur.PonyStealer.MLT.1
MicroWorld-eScanGen:Heur.PonyStealer.MLT.1
Ad-AwareGen:Heur.PonyStealer.MLT.1
SophosML/PE-A
ComodoTrojWare.Win32.TrojanSpy.Bancos.KHO@5rvpl2
BitDefenderThetaAI:Packer.10E02D2E20
VIPRELooksLike.Win32.Malware!vb (v)
McAfee-GW-EditionRDN/Generic PWS.y
FireEyeGeneric.mg.0512969b9150edb6
EmsisoftGen:Heur.PonyStealer.MLT.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.1D18EA9
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.PonyStealer.MLT.1
GDataGen:Heur.PonyStealer.MLT.1
AhnLab-V3Trojan/Win32.Cossta.R218005
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=84)
MalwarebytesTrojan.Banker
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!mK1fh9obrmo
IkarusTrojan-PWS.Banker6
FortinetW32/Bancos.ACMB!tr
AVGWin32:GenMalicious-XO [Trj]
Qihoo-360Win32/Ransom.FRS.HwMAueAA

How to remove Trojan.Win32.Cossta.ajjf?

Trojan.Win32.Cossta.ajjf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment