Trojan

Should I remove “Trojan-Downloader.Win32.Agent.xxzrjh”?

Malware Removal

The Trojan-Downloader.Win32.Agent.xxzrjh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.xxzrjh virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to create or modify system certificates
  • Generates some ICMP traffic

Related domains:

z.whorecord.xyz
a.tomx.xyz
baidu.com
flashdownloadserver.oss-cn-hongkong.aliyuncs.com

How to determine Trojan-Downloader.Win32.Agent.xxzrjh?


File Info:

crc32: A7551EBC
md5: e8cafc82f8c9c3e2aee4c0958a895f00
name: E8CAFC82F8C9C3E2AEE4C0958A895F00.mlw
sha1: 89f8277e8914837f15b8753844e0ff63a435b6e2
sha256: 3e8f8b8a5f70c195a2e4d4fc7f80523809f6dbf9ead061ce8ef04fb489a577cf
sha512: ff7f23ebf639134f6756ded7fe578c1d4be312e9fba0309d6154d82bc01031a82ec3bd702f464d2b706996c82c74687edf37cf078c9e3dcf3ad373526ae73a68
ssdeep: 49152:f/QlJmmEeBMZ7NK8gzQLcb2IDBc1qIxddntTl7HhMRpPS8HBx8xwIGjg+ARDTjz:f/uvEeecbFDBsd5tTlr4H/q+Ad
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Agent.xxzrjh also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.DownLoader40.37731
ALYacBackdoor.Agent.Biopass
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
K7GWRiskware ( 0040eff71 )
ESET-NOD32a variant of WinGo/TrojanDownloader.Agent.AB
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Agent.xxzrjh
BitDefenderTrojan.GenericKD.37224934
ViRobotBackdoor.Win32.S.Biopass.4916736.A
MicroWorld-eScanTrojan.GenericKD.37224934
Ad-AwareTrojan.GenericKD.37224934
SophosMal/Generic-S
ComodoMalware@#245baddgrt35m
BitDefenderThetaAI:Packer.8DFD1E5521
TrendMicroBackdoor.Win32.BIOPASS.A
McAfee-GW-EditionBehavesLike.Win32.Generic.rm
FireEyeTrojan.GenericKD.37224934
EmsisoftTrojan.GenericKD.37224934 (B)
WebrootW32.Malware.Gen
AviraTR/Redcap.jjbfv
KingsoftWin32.TrojDownloader.Agent.(kcloud)
MicrosoftTrojan:Win32/Casdet!rfn
ZoneAlarmTrojan-Downloader.Win32.Agent.xxzrjh
GDataTrojan.GenericKD.37224934
McAfeeGenericRXAA-AA!E8CAFC82F8C9
MAXmalware (ai score=80)
MalwarebytesMalware.AI.1957324561
TrendMicro-HouseCallBackdoor.Win32.BIOPASS.A
RisingTrojan.Generic@ML.89 (RDMK:ic2FJa4kwPfP+0yEsUusSw)
IkarusTrojan.Win64.Ranumbot
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Agent.xxzrjh?

Trojan-Downloader.Win32.Agent.xxzrjh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment