Trojan

Trojan.Agent.XN removal instruction

Malware Removal

The Trojan.Agent.XN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.XN virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.XN?


File Info:

crc32: 116637C0
md5: b69db6d659ae29ffecf7aa297b985cd9
name: server.exe
sha1: e74246457b829a8f0b8b2d0aaecb3a38e25e2041
sha256: 6fc6b49f28d1b48bde289cc7ffdd5d41733afb4ae730e3a1782e3c105e69d837
sha512: dc9925123a20274b4d80b6d0c1636cf42e2fca98914497f30299381df91425e66f2e93f9a4d110cf4f8a41947ab8c55baec8af087ca5adabbce8d449d8e104a1
ssdeep: 12288:qJi16yAc5TmNGxochOYyE0WLW3IzFTtJQa81h:qscynTD2KTPxTtJuf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.XN also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.31922148
FireEyeGeneric.mg.b69db6d659ae29ff
CAT-QuickHealTrojan.GenericCS.S209117
McAfeeGenericR-APN!B69DB6D659AE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderTrojan.GenericKD.31922148
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.659ae2
Invinceaheuristic
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-485474
GDataTrojan.GenericKD.31922148
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.36269450
NANO-AntivirusTrojan.Win32.MlwGen.bcbfqc
RisingTrojan.Delf!8.67 (CLOUD)
Ad-AwareTrojan.GenericKD.31922148
SophosMal/Generic-S
ComodoMalware@#2k4i1jsgk1d0u
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoader7.30425
ZillyaTrojan.Delf.Win32.57485
TrendMicroHT_ZYX_GC09017C.UVPM
McAfee-GW-EditionGenericR-APN!B69DB6D659AE
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.31922148 (B)
IkarusTrojan.Win32.Spy2
JiangminTrojan/Generic.ysut
MaxSecureTrojan.Malware.7164915.susgen
AviraTR/ATRAPS.Gen
MAXmalware (ai score=100)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E717E4
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Agent.R200351
BitDefenderThetaAI:Packer.BB139DDE21
ALYacTrojan.GenericKD.31922148
VBA32Trojan.Downloader
MalwarebytesTrojan.Agent.XN
PandaGeneric Malware
ESET-NOD32Win32/Delf.OIN
TrendMicro-HouseCallHT_ZYX_GC09017C.UVPM
TencentMalware.Win32.Gencirc.10b68dce
YandexTrojan.Agent!gJLYyoskees
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Generic.OIN!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Dropper.2ff

How to remove Trojan.Agent.XN?

Trojan.Agent.XN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment