Trojan

Should I remove “Win32/TrojanDownloader.Agent.FJL”?

Malware Removal

The Win32/TrojanDownloader.Agent.FJL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.FJL virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

keeperfile.atwebpages.com
nicovsh.ddns.net

How to determine Win32/TrojanDownloader.Agent.FJL?


File Info:

crc32: 1A7B2FBD
md5: 17d6fb7249d7cf29404e4b604f38a35c
name: upload_file
sha1: 8660283f1dd38d08004390b5729603ff11b0d842
sha256: e4ae2cb5ba91a9b7a87cb5d79158e07f8252e8c3ad0649fca573a0d73bbbdc62
sha512: 08b8731489920c0fc2042251a7391ee200eb761c33c836f2e3759ca8ec4d389f589790931a675633622b561b4878a5e248af999f18e46ba7ef4fa0044ff95c7d
ssdeep: 1536:cO8kfpq+5b97EYxqwN4HE60Ja2QyfI/gpp+J4FeonntsWEl5tcd6vVH9VT:DrxqNHr0Ja2QyQEVey6a6vVHT
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.FJL also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34745230
FireEyeGeneric.mg.17d6fb7249d7cf29
ALYacTrojan.GenericKD.34745230
AegisLabTrojan.Win32.Androm.m!c
BitDefenderTrojan.GenericKD.34745230
K7GWTrojan-Downloader ( 00570eb51 )
BitDefenderThetaGen:NN.ZexaF.34298.gCW@aKqc9Cei
SymantecML.Attribute.HighConfidence
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Androm.gen
AlibabaBackdoor:Win32/Androm.caf3a5be
ViRobotTrojan.Win32.Z.Agent.103424.ZF
Ad-AwareTrojan.GenericKD.34745230
EmsisoftTrojan.GenericKD.34745230 (B)
ComodoMalware@#2j9izime0gf6
F-SecureBackdoor.BDS/Androm.rqsvo
DrWebTrojan.Siggen10.36598
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_99%
AviraBDS/Androm.rqsvo
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Ymacco.AAE4
ArcabitTrojan.Generic.D2122B8E
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
GDataTrojan.GenericKD.34745230
CynetMalicious (score: 85)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FJL
McAfeeArtemis!17D6FB7249D7
MalwarebytesSpyware.LokiBot
PandaTrj/GdSda.A
ZonerTrojan.Win32.95803
SentinelOneDFI – Suspicious PE
FortinetPossibleThreat.MU
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM10.2.84DF.Malware.Gen

How to remove Win32/TrojanDownloader.Agent.FJL?

Win32/TrojanDownloader.Agent.FJL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment