Malware

What is “Win32:Downloader-EYJ [Trj]”?

Malware Removal

The Win32:Downloader-EYJ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Downloader-EYJ [Trj] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Enumerates running processes
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Fake User-Agent detected
  • Anomalous binary characteristics

How to determine Win32:Downloader-EYJ [Trj]?


File Info:

name: A397B204D4622D5482A3.mlw
path: /opt/CAPEv2/storage/binaries/f15e69c2b744a8cc94b144c753978d45d81ad0cf5f59b533ae826daa34fd4b6e
crc32: E4A27A42
md5: a397b204d4622d5482a398e65707fd30
sha1: d753c25e9a56b0cfe6a23d431d9b264c194f5c0e
sha256: f15e69c2b744a8cc94b144c753978d45d81ad0cf5f59b533ae826daa34fd4b6e
sha512: ef58f818292075960c7e4886e3a4ac9a5ec6fd9edaf317ba9a65be390a4df6a1d3e91fbf41c42eae20232e6dec93b8bbf084076eaaea33b24d9b444a9bb427e5
ssdeep: 98304:XnHNcpPsBt8nNIKt872XXrK6qYyib1TFqFBDNtYKb9VOb6VYnVjAUsMVNM4PGDfe:XkCKLXbK6qYyAToFBJtYKpVMjAvd764Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6862371BFC5C0BBCD82A436441EE39E4276F5618F3245C3A59D2B2DEB306D20E39696
sha3_384: 05e8698860e04d0c374f039b9ea77d540159570743bf689822cb432ec830081424734fd23128ea6b832a39e49df5443b
ep_bytes: e878730000e979feffff6a0c68704750
timestamp: 2010-11-17 03:29:06

Version Info:

0: [No Data]

Win32:Downloader-EYJ [Trj] also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen2.64055
MicroWorld-eScanGen:Trojan.Dropper.RQU.@FZ@aijH@Wji
FireEyeGeneric.mg.a397b204d4622d54
CAT-QuickHealTrojan.Sefnit.L7
ALYacGen:Trojan.Dropper.RQU.@FZ@aijH@Wji
CylanceUnsafe
ZillyaTrojan.Agent.Win32.141878
K7AntiVirusTrojan ( 00317af61 )
K7GWTrojan ( 00317af61 )
Cybereasonmalicious.4d4622
BitDefenderThetaGen:NN.ZexaF.34182.@FZ@aijH@Wji
CyrenW32/Sefnit.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.WRY
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Dropper.RQU.@FZ@aijH@Wji
NANO-AntivirusTrojan.Win32.TrjGen.ctmowt
AvastWin32:Downloader-EYJ [Trj]
TencentMalware.Win32.Gencirc.114c84e1
SophosML/PE-A + Mal/Sulhanen-A
ComodoTrojWare.Win32.Agent.wry@2mb5bo
VIPREBackdoor.Win32.Agent.ABHO (v)
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
EmsisoftGen:Trojan.Dropper.RQU.@FZ@aijH@Wji (B)
AviraTR/Sefnit.OK
Antiy-AVLTrojan/Generic.ASMalwS.DDBCA
MicrosoftTrojan:Win32/Sefnit.L
GDataGen:Trojan.Dropper.RQU.@FZ@aijH@Wji
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Antisb.R1975
McAfeeGeneric BackDoor.rq
MAXmalware (ai score=85)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.3328771184
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazq8sOosZa8Xt/P4NMfUeBH3)
YandexTrojan.GenAsa!3EU96a/oWz8
IkarusGen.Variant.Buzy
FortinetW32/BanLoader.AAAD!tr
AVGWin32:Downloader-EYJ [Trj]
PandaTrj/CI.A

How to remove Win32:Downloader-EYJ [Trj]?

Win32:Downloader-EYJ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment