Trojan

Trojan-Downloader.Win32.Agent.xxzrje (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Agent.xxzrje is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.xxzrje virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to create or modify system certificates
  • Generates some ICMP traffic

Related domains:

baidu.com
flashdownloadserver.oss-cn-hongkong.aliyuncs.com

How to determine Trojan-Downloader.Win32.Agent.xxzrje?


File Info:

crc32: 32F10190
md5: 707e8f7fd1775c7f5a0928e5061c93e1
name: 707E8F7FD1775C7F5A0928E5061C93E1.mlw
sha1: ec6b4a8f8ad33aad1bcaa49ee247e56585ebfda6
sha256: 344cdbc2a7e0908cb6638bc7b81b6b697b32755bad3bed09c511866eff3876c7
sha512: 45a2c9fd02fe21a1bdcb8140f1bf0a709e787f243cb3b669008a8aa3e2f4b3daba1f393165632cc75e7bef40eecea99e2b786fd42892ed4ee4628153716c61e6
ssdeep: 49152:AuC9ItEeAMF7tK8hYuE+T1yDIH9kVrdY1sQlV/4UXR6MpBVhXjnwIGjg+AWDTjzp:AzWEeW+TMDIkd8sQlVwCVlf+Am
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Agent.xxzrje also known as:

DrWebTrojan.Siggen14.35364
ALYacBackdoor.Agent.Biopass
MalwarebytesMalware.AI.1957324561
SangforTrojan.Win32.Agent.xxzrje
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of WinGo/TrojanDownloader.Agent.AB
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Downloader.Win32.Agent.xxzrje
BitDefenderTrojan.GenericKD.37224913
ViRobotBackdoor.Win32.S.Biopass.4923480
MicroWorld-eScanTrojan.GenericKD.37224913
Ad-AwareTrojan.GenericKD.37224913
SophosMal/Generic-S
ComodoMalware@#30yzkwwjtp1ir
TrendMicroBackdoor.Win32.BIOPASS.A
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.37224913
EmsisoftTrojan.GenericKD.37224913 (B)
WebrootW32.Trojan.Biopass
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
ZoneAlarmTrojan-Downloader.Win32.Agent.xxzrje
GDataTrojan.GenericKD.37224913
McAfeeGenericRXAA-AA!707E8F7FD177
MAXmalware (ai score=89)
TrendMicro-HouseCallBackdoor.Win32.BIOPASS.A
IkarusTrojan.Win64.Ranumbot
AVGWin32:Malware-gen

How to remove Trojan-Downloader.Win32.Agent.xxzrje?

Trojan-Downloader.Win32.Agent.xxzrje removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment