Trojan

Win32/TrojanDownloader.Agent.EJX removal

Malware Removal

The Win32/TrojanDownloader.Agent.EJX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.EJX virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Uses XCOPY for copying files

How to determine Win32/TrojanDownloader.Agent.EJX?


File Info:

name: 26F7608D193D6E7E486B.mlw
path: /opt/CAPEv2/storage/binaries/29efcf6018d95f1a75207d9f39657a2da416a558e6041f63904699b3a74dff01
crc32: 9ADEDF47
md5: 26f7608d193d6e7e486bed686a0456f0
sha1: 8c440ce616b96153e2a2937d4f16260c802262b7
sha256: 29efcf6018d95f1a75207d9f39657a2da416a558e6041f63904699b3a74dff01
sha512: bf82ff98ede1d803509833c00d6ae1c65228cd543b3bc98fd27166a4ab235da40b61bb3d52edab587ef8c7e9822386a446c16e16ed204ebdbec811409ba0c096
ssdeep: 6144:SLXQpSB0KdW9bLdHjUgw/Aeu1Nbf6IQhosjaYSrhMng0otJn/5867T3EovpVAN9F:SbQMB0KW99n/jbwpaR2nz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B949E59B9CB98F2EB025179459BE37B0338BD4149166BA3FBD17F3B1D32A827C44209
sha3_384: d7a68d572a660c43e73c28822aa6f96ff2a3e3fb41e2c6c35f94c71dfee49c3444e964b16449084f49f96d6847066af5
ep_bytes: 83ec1cc7042402000000ff151c224200
timestamp: 2012-12-02 00:33:50

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.EJX also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader19.63332
FireEyeGeneric.mg.26f7608d193d6e7e
Cylanceunsafe
SangforDownloader.Win32.Agent.Vynw
K7AntiVirusTrojan-Downloader ( 005515291 )
AlibabaTrojanDownloader:Win32/Generic.e00192a4
K7GWTrojan-Downloader ( 005515291 )
Cybereasonmalicious.616b96
VirITTrojan.Win32.DownLoader19.DPRW
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.EJX
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.Dwn.fmgqal
AvastFileRepMalware [Trj]
TencentWin32.Trojan-Downloader.Oader.Ltgl
SophosMal/Generic-S
ZillyaDownloader.Agent.Win32.383100
McAfee-GW-EditionBehavesLike.Win32.Worm.gh
Trapminesuspicious.low.ml.score
WebrootW32.Trojan.Gen
XcitiumSuspicious@#2hqgijd3a2qy8
VBA32suspected of Trojan.Downloader.gen
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
APEXMalicious
RisingDownloader.Agent!8.B23 (CLOUD)
AVGFileRepMalware [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/TrojanDownloader.Agent.EJX?

Win32/TrojanDownloader.Agent.EJX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment