Worm

Worm.Agent.XJ3 removal

Malware Removal

The Worm.Agent.XJ3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Agent.XJ3 virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Worm.Agent.XJ3?


File Info:

crc32: AF35CC5B
md5: 1081799862c060c47453daa22877ffdb
name: normal_5ce36bb63bf4a.exe
sha1: bc270d4da09d965cc2e5f98d26bf486df7e48932
sha256: 20e9f024ee45f6f6e94d920dd8f256e3dc003d06df05376c67331f5d5e01c55b
sha512: 813a9422c5e4063d2de0c339a41a838ae33a0e000f93e3fa148b20943ee62c327d28ee5ed9e0c2bf9cfeafc70450265dfcf737f8629ffa735187275e3154f291
ssdeep: 98304:ebEsBKXEkq6PK2qoYLoE7HqWtMZNpWFSaNNgoyN+1Vb07eF30z1FgH+ggGq+3Ko7:AFEXxpP5qosuvWoKNqM1C7eFkZFZzGDp
type: MS-DOS executable, MZ for MS-DOS

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: TJprojMain
FileVersion: 1.00
OriginalFilename: TJprojMain.exe
ProductName: Project1

Worm.Agent.XJ3 also known as:

BkavW32.WatermarkHQc.PE
MicroWorld-eScanGen:Variant.Razy.102592
CAT-QuickHealWorm.Agent.XJ3
ALYacGen:Variant.Razy.102592
MalwarebytesTrojan.Banker
ZillyaVirus.HLLP.Win32.1
TheHackerTrojan/Downloader.VB.qcc
K7GWTrojan-Downloader ( 0011507f1 )
K7AntiVirusTrojan-Downloader ( 0011507f1 )
Invinceaheuristic
BaiduWin32.Worm.VB.b
F-ProtW32/TJtroj.A.gen!Eldorado
SymantecW32.Gosys
TotalDefenseWin32/Tnega.SHMfXW
TrendMicro-HouseCallPE_SWISB.A
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1109049
KasperskyTrojan.Win32.Agent.xjgj
BitDefenderGen:Variant.Razy.102592
NANO-AntivirusTrojan.Win32.Agent.cqkyjd
AegisLabTroj.W32.Agent.tnrh
RisingTrojan.Agent!1.6A70 (cloud:Qd69twciY7T)
Ad-AwareGen:Variant.Razy.102592
SophosTroj/Agent-ABZF
ComodoTrojWare.Win32.VB.QOTY
F-SecureGen:Variant.Razy.102592
DrWebWin32.HLLP.Swisyn
VIPRETrojan.Win32.Agent.abzf (v)
TrendMicroPE_SWISB.A
McAfee-GW-EditionBehavesLike.Win32.Swisyn.tc
EmsisoftGen:Variant.Razy.102592 (B)
IkarusWorm.Mofksys
CyrenW32/TJtroj.A.gen!Eldorado
JiangminTrojan/Agent.hxgb
WebrootW32.Malware.Gen
AviraWORM/Mofksys.bouem
FortinetW32/VB.QCC!tr.dldr
KingsoftWin32.Troj.Agent.xj.(kcloud)
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D190C0
ZoneAlarmTrojan.Win32.Agent.xjgj
MicrosoftVirus:Win32/Mofksys.B
AhnLab-V3Trojan/Win32.Swisyn.R1452
McAfeeW32/Swisyn.ai
AVwareTrojan.Win32.Agent.abzf (v)
VBA32Trojan.Agent
PandaTrj/Spy.AT
ESET-NOD32a variant of Win32/VB.QOT
TencentWin32.Trojan.Agent.Dvzl
YandexTrojan.Agent!4gxD+wIprsY
SentinelOnestatic engine – malicious
GDataGen:Variant.Razy.102592
AVGWin32:VB-OJQ [Wrm]
AvastWin32:VB-OJQ [Wrm]
CrowdStrikemalicious_confidence_100% (D)
Qihoo-360Win32/Trojan.ad7

How to remove Worm.Agent.XJ3?

Worm.Agent.XJ3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment