Malware

Win64/Agent.ZJ removal instruction

Malware Removal

The Win64/Agent.ZJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Agent.ZJ virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Win64/Agent.ZJ?


File Info:

crc32: 9A9A72C9
md5: 8df09f51a6fa1bcfe3c021ddb16829ff
name: 8DF09F51A6FA1BCFE3C021DDB16829FF.mlw
sha1: d9c7d290c34a301b5aff5905977e1a277d47c8d6
sha256: b44d4863b5b989587a20e4d7a3c19564275321b4b5d9a4345b323f2cbba69d4f
sha512: 9b6beef8532caaf325f095461a7309cbefe41a3702cefc1e935956f12a389a8efcf7c806c2587d490569d93df6ddec7082892f537bc81a5ee27d53fc54821d15
ssdeep: 3072:KJZldiHXSXMblWPx3zQGy/4+9tZ1EjiIrWMS6xfMZn2nsetbbGeBvDTQkJ0p:KJZl0mMbUz7y/vL+jb1S2/ZnV
type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: EventSystem.dll
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Com+ Microsoft Service
OriginalFilename: EventSystem.dll
Translation: 0x0804 0x04b0

Win64/Agent.ZJ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.14737
ALYacTrojan.GenericKD.44494197
CylanceUnsafe
ZillyaTrojan.Inject.Win32.308151
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win64/Inject.c3df84c3
K7GWTrojan ( 00568db11 )
K7AntiVirusTrojan ( 00568db11 )
CyrenW64/Trojan.EJFV-5429
SymantecTrojan.Gen.MBT
ESET-NOD32Win64/Agent.ZJ
APEXMalicious
AvastWin64:Trojan-gen
KasperskyTrojan.Win32.Inject.anlhu
BitDefenderTrojan.GenericKD.44494197
NANO-AntivirusTrojan.Win64.Inject.iczlth
MicroWorld-eScanTrojan.GenericKD.44494197
TencentWin32.Trojan.Inject.Egeq
Ad-AwareTrojan.GenericKD.44494197
SophosMal/Generic-S
ComodoMalware@#1tawn93adfasz
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WKH20
McAfee-GW-EditionBehavesLike.Win64.Fake.cc
FireEyeGeneric.mg.8df09f51a6fa1bcf
EmsisoftTrojan.GenericKD.44494197 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.bnkf
MicrosoftTrojan:Win32/Ymacco.AAB4
ArcabitTrojan.Generic.D2A6ED75
AegisLabTrojan.Win32.Inject.4!c
ZoneAlarmTrojan.Win32.Inject.anlhu
GDataTrojan.GenericKD.44494197
McAfeeArtemis!8DF09F51A6FA
MAXmalware (ai score=85)
VBA32Trojan.Wacatac
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WKH20
RisingTrojan.Agent!8.B1E (CLOUD)
YandexTrojan.Inject!IbtpdlvJD+I
IkarusTrojan.Win64.Agent
MaxSecureTrojan.Malware.109655873.susgen
FortinetW32/Inject.ANLHU!tr
AVGWin64:Trojan-gen
Paloaltogeneric.ml

How to remove Win64/Agent.ZJ?

Win64/Agent.ZJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment