Spy

Win32/Spy.Agent.PJP malicious file

Malware Removal

The Win32/Spy.Agent.PJP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.PJP virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Mimics icon used for popular non-executable file format

How to determine Win32/Spy.Agent.PJP?


File Info:

name: EE49961547877A18480E.mlw
path: /opt/CAPEv2/storage/binaries/77de59e9cea26a2d645ab371ae6a88c427b5c7cf802dd039a5361b648ffb70e6
crc32: 2771656E
md5: ee49961547877a18480e22f4076f95f2
sha1: 79bacd047841382aa06dc397f4952cbf03d07c3c
sha256: 77de59e9cea26a2d645ab371ae6a88c427b5c7cf802dd039a5361b648ffb70e6
sha512: f2c7716470f73912f7151687449a0f6d294b733ec9a985b61200cefed13cddab7982d85a4d3a5520b067b3b7195119415fea146af2cb19166cd93610fc6292f4
ssdeep: 196608:jVQer8aeEoj7jM66MtxEy+BRa0YcL715z14l:Mzj7jP6cxE/RvY6552
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164E6830399048746E46942F5BE570EAC2F1A2E1C9BD529EF10572ECB3A353F21D7E12E
sha3_384: 5265a52c65c3b665229c3950b06be1c02306a04766904bda9ac6465127e87bc92dd6624e424eb1a77e1690f8c04ebeb9
ep_bytes: e91f501200e9fa1e1800e9b5600500e9
timestamp: 2018-02-11 13:06:25

Version Info:

0: [No Data]

Win32/Spy.Agent.PJP also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.61111765
FireEyeGeneric.mg.ee49961547877a18
ALYacTrojan.GenericKD.61111765
ZillyaTrojan.Agent.Win32.880738
SangforSpyware.Win32.Apost.Vfmi
BitDefenderTrojan.GenericKD.61111765
Cybereasonmalicious.547877
ArcabitTrojan.Generic.D3A47DD5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.PJP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.APosT.cxd
AlibabaTrojanSpy:Win32/APosT.dc09b56f
NANO-AntivirusTrojan.Win32.TrjGen.eygbfv
ViRobotTrojan.Win32.S.Agent.14280192
RisingSpyware.Agent!8.C6 (CLOUD)
Ad-AwareTrojan.GenericKD.61111765
SophosMal/Generic-S
ComodoMalware@#16i37ovjy0p33
DrWebTrojan.Siggen7.36181
VIPRETrojan.GenericKD.61111765
TrendMicroTROJ_FRS.0NA103D920
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.GenericKD.61111765 (B)
IkarusTrojan-Spy.Agent
GoogleDetected
AviraTR/Spy.Agent.enmvm
Antiy-AVLTrojan/Generic.ASMalwS.4B1C
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.61111765
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2434341
McAfeeGenericRXAA-AA!EE4996154787
MAXmalware (ai score=98)
VBA32BScope.TrojanPSW.Agent
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103D920
TencentWin32.Trojan.Apost.Pqil
YandexTrojan.GenAsa!C8YYOYxJsGA
MaxSecureTrojan.Malware.12137193.susgen
FortinetW32/Spy.AGENT.PJP!tr
BitDefenderThetaGen:NN.ZexaF.34698.@NW@ayAMBafO
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Spy.Agent.PJP?

Win32/Spy.Agent.PJP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment