Trojan

Trojan-Downloader.Win32.Agent.xxzrjc malicious file

Malware Removal

The Trojan-Downloader.Win32.Agent.xxzrjc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.xxzrjc virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to create or modify system certificates
  • Generates some ICMP traffic

Related domains:

baidu.com
flashdownloadserver.oss-cn-hongkong.aliyuncs.com
www.flash.cn

How to determine Trojan-Downloader.Win32.Agent.xxzrjc?


File Info:

crc32: D31D5C81
md5: 4ed409f5fcd0a2a0990e204f84f21de8
name: 4ED409F5FCD0A2A0990E204F84F21DE8.mlw
sha1: 3a0971a00e9a7709f2fbcafd09ac3e248f558117
sha256: 09530096643b835cff71a1e48020866fd0d4d0f643fe07f96acdcd06ce11dfa4
sha512: 43eca1bc8399201907ac0d430b9733c4b71f56fffa49d38f7dc9b1e9256ba0964ea4a9f1022f1abc03471683b24079dfe7e743b2ed76631d39834170c78885d8
ssdeep: 98304:Omdq3ILZDLp3Dr86I2k+AsBK3sthWnNPhHNKnYLzg8:OCq38qlsgkQnvHhLc8
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Agent.xxzrjc also known as:

DrWebTrojan.Siggen14.35363
ALYacBackdoor.Agent.Biopass
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
ESET-NOD32a variant of WinGo/TrojanDownloader.Agent.AB
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Downloader.Win32.Agent.xxzrjc
BitDefenderTrojan.GenericKD.37224911
ViRobotBackdoor.Win32.S.Biopass.6155264
MicroWorld-eScanTrojan.GenericKD.37224911
Ad-AwareTrojan.GenericKD.37224911
SophosMal/Generic-S
ComodoMalware@#1fsthfpwpwwjm
BitDefenderThetaGen:NN.ZexaF.34790.@@W@au0cIvbi
TrendMicroBackdoor.Win32.BIOPASS.A
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeTrojan.GenericKD.37224911
EmsisoftTrojan.GenericKD.37224911 (B)
WebrootW32.Trojan.Gen
KingsoftWin32.TrojDownloader.Agent.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
GDataTrojan.GenericKD.37224911
McAfeeArtemis!4ED409F5FCD0
MAXmalware (ai score=89)
TrendMicro-HouseCallBackdoor.Win32.BIOPASS.A
RisingTrojan.Generic@ML.89 (RDMK:MQ7RhVcTcQjvz9Nx+hTkuw)
IkarusTrojan.Win64.Ranumbot
AVGWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Agent.xxzrjc?

Trojan-Downloader.Win32.Agent.xxzrjc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment