Trojan

How to remove “Trojan-Downloader.Win32.Agent.xxycta”?

Malware Removal

The Trojan-Downloader.Win32.Agent.xxycta is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.xxycta virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

kr01.ipv2.xyz
apps.identrust.com

How to determine Trojan-Downloader.Win32.Agent.xxycta?


File Info:

crc32: F931C554
md5: be2d9a745f784307300026164b93d073
name: BE2D9A745F784307300026164B93D073.mlw
sha1: bbcbc999a2e486d79997c6b4109e50bc5ae11afb
sha256: 2175485d7e9240e6dd0e0963d8f52a938cff4977a351230cb32d97baa54beea5
sha512: 8647f86f9b215ae720f133796ecb396c93b00a96f4c94be2645b4f9e05844a44d6e7aadf158597506db126fa277472982565b29e9246a766a90ed44dec912229
ssdeep: 6144:MrojxhzSjo6KCD4SLNdcrvUL11Nup7RGv7qwoSavQ9G/JRt7g0g:vjxhzO5KC1Qcc7G2ZtiGxY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: 91023810
Comments: This installation was built with Inno Setup.
ProductName: 91023810
ProductVersion: 1.0.0.3
FileDescription: 91023810 Setup
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Agent.xxycta also known as:

K7AntiVirusTrojan ( 004a66261 )
LionicTrojan.Win32.Agent.a!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.39498
CynetMalicious (score: 99)
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004a66261 )
Cybereasonmalicious.9a2e48
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.DZZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Downloader.Win32.Agent.xxycta
NANO-AntivirusTrojan.Win32.Dwn.fegsbn
TencentWin32.Trojan-downloader.Agent.Pgmv
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionDownloader-FBSI!BE2D9A745F78
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1124690
MicrosoftTrojan:Win32/Skeeyah.A!rfn
AhnLab-V3Malware/Win32.Generic.C2499158
McAfeeDownloader-FBSI!BE2D9A745F78
MAXmalware (ai score=97)
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
YandexTrojan.DL.Agent!QApjzQfv6lE
IkarusTrojan.Downloader.Inno.Agent
FortinetW32/Agent.EBX!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Agent.xxycta?

Trojan-Downloader.Win32.Agent.xxycta removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment