Trojan

Trojan-Downloader.Win32.Agent.xxzpns removal tips

Malware Removal

The Trojan-Downloader.Win32.Agent.xxzpns is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.xxzpns virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
HkZGYKBbdYjgbZdenNrlsSsxObwZj.HkZGYKBbdYjgbZdenNrlsSsxObwZj

How to determine Trojan-Downloader.Win32.Agent.xxzpns?


File Info:

crc32: 24512441
md5: 8db0eec92d4378a23311ddaa8724542b
name: 8DB0EEC92D4378A23311DDAA8724542B.mlw
sha1: dff075afc4cf8d913c02fd0863dc897a4fa9f26c
sha256: 80f790a2fb15bcc709dbc1719e6373113de2a057ec4f69c5c36a8fb8e578f781
sha512: 72106e5d20106b180196be6e76fe5ee039c9107c293a45963a8557f7490395c7f5acc6cca711f184dbd6eb715070a7a613e04c18cc95a64802bf9e9aa1339abb
ssdeep: 49152:g5+hFESLVW29p5YO7lDXJGHZHNBW30yUxlgY8JnEpj0:g5aFfq5BryOKhpEpA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Jwcpesx
FileVersion: 6.96.7229.03166 (yyfszbu_vja.347806-5591)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 6.96.7229.03166
FileDescription: Qoq10 Mkgnbll Eumvejshsh
OriginalFilename: KVYNAIJ.EXE .PQX
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Agent.xxzpns also known as:

BkavW32.AIDetectGBM.malware.02
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36385917
Qihoo-360Win32/TrojanDownloader.Generic.HyoDfMcA
McAfeeArtemis!8DB0EEC92D43
VIPREWin32.Malware!Drop
SangforTrojan.Win32.Woreflint.A
K7AntiVirusTrojan ( 005782a31 )
BitDefenderTrojan.GenericKD.36385917
K7GWTrojan ( 005782a31 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Trojan.COXP-7372
SymantecML.Attribute.HighConfidence
AvastFileRepMalware
KasperskyTrojan-Downloader.Win32.Agent.xxzpns
AlibabaTrojanDownloader:Win32/Generic.ecf8fa7b
AegisLabTrojan.Win32.Agent.a!c
RisingTrojan.HiddenRun/SFX!1.D2BC (CLASSIC)
Ad-AwareTrojan.GenericKD.36385917
EmsisoftTrojan.GenericKD.36385917 (B)
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.8db0eec92d4378a2
SophosMal/Generic-S
WebrootW32.Trojan.Gen
KingsoftWin32.TrojDownloader.Agent.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA80
GridinsoftTrojan.Win32.Agent.ns
ArcabitTrojan.Generic.D22B347D
ZoneAlarmTrojan-Downloader.Win32.Agent.xxzpns
GDataTrojan.GenericKD.36385917
ALYacTrojan.GenericKD.36385917
MAXmalware (ai score=83)
MalwarebytesTrojan.Dropper.WXT.Generic
PandaTrj/Agent.JMA
ESET-NOD32a variant of Win32/Packed.7zip.A suspicious
TrendMicro-HouseCallTROJ_GEN.R011H0CBO21
TencentWin32.Trojan-downloader.Agent.Eerg
eGambitPE.Heur.InvalidSig
FortinetW32/7Zip.N!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Agent.xxzpns?

Trojan-Downloader.Win32.Agent.xxzpns removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment