Trojan

Trojan-Downloader.Win32.Agent.xxyack removal guide

Malware Removal

The Trojan-Downloader.Win32.Agent.xxyack is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.xxyack virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Agent.xxyack?


File Info:

name: C956D8085789800D3725.mlw
path: /opt/CAPEv2/storage/binaries/230d8f0c6c5c64c63f4ad12c4a809368fc0d03e6cad9470ef4013ec4c4fc3894
crc32: E1E8D359
md5: c956d8085789800d37253e19cb1714b8
sha1: dd672f7da16390b8f3264e307efd592604744475
sha256: 230d8f0c6c5c64c63f4ad12c4a809368fc0d03e6cad9470ef4013ec4c4fc3894
sha512: 4ec98bc454079b0b5547513e2ba55b88f5e1b336f85f368eb7a63e1179f1549b86cde240acd60480be8c832bf5e370751a9109a244ac30d6552cba50a744500f
ssdeep: 6144:MrojxFSkhSjo6KCD4SLNdcrvUL11Nup7RGv7qwoSavQ9G/JRt7g0g:vjxFjO5KC1Qcc7G2ZtiGxY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4640202E6D588B2E170DEB41E2DA0049A377E262C74602D37DC5ECD8F376E19A5B793
sha3_384: 03d9c333c84dc0597be7e003a80d8d22442969724e24649bfe15e1105123d6858a22cd5daa3886dadf961e9881363a92
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: EasyLook
FileDescription: EasyLook Setup
FileVersion:
LegalCopyright:
ProductName: EasyLook
ProductVersion: 1.0.0.3
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Agent.xxyack also known as:

LionicTrojan.Win32.Agent.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.94450
FireEyeGen:Variant.Cerbu.94450
ALYacGen:Variant.Cerbu.94450
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00534de11 )
BitDefenderGen:Variant.Cerbu.94450
K7GWTrojan ( 00534de11 )
CrowdStrikewin/malicious_confidence_80% (W)
CyrenW32/Delf.IB.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.DZZ
TrendMicro-HouseCallTROJ_GEN.R002C0PKM21
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Agent.xxyack
NANO-AntivirusTrojan.Win32.Dwn.fcsgky
TencentWin32.Trojan-downloader.Agent.Syrm
Ad-AwareGen:Variant.Cerbu.94450
SophosMal/Generic-S
DrWebTrojan.DownLoader26.47966
ZillyaDownloader.Agent.Win32.352673
McAfee-GW-EditionDownloader-FBSI!C956D8085789
EmsisoftGen:Variant.Cerbu.94450 (B)
IkarusTrojan.Downloader.Inno.Agent
AviraHEUR/AGEN.1124690
MicrosoftTrojan:Win32/Wacatac.B!ml
APEXMalicious
GDataGen:Variant.Cerbu.94450
CynetMalicious (score: 99)
AhnLab-V3Malware/Gen.Generic.C2544116
McAfeeDownloader-FBSI!C956D8085789
MAXmalware (ai score=83)
MalwarebytesTrojan.Downloader
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.EBX!tr.dldr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan-Downloader.Win32.Agent.xxyack?

Trojan-Downloader.Win32.Agent.xxyack removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment