Trojan

Trojan-Downloader.Win32.Agent.xyairi removal

Malware Removal

The Trojan-Downloader.Win32.Agent.xyairi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.xyairi virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan-Downloader.Win32.Agent.xyairi?


File Info:

name: FBDE15800EF8C6E7EBAB.mlw
path: /opt/CAPEv2/storage/binaries/e6a7f146e5a355e832039fe246fcf124f2f2a5eb2471b4a6dced06735c17fa5e
crc32: 1E3B86CD
md5: fbde15800ef8c6e7ebab4aa645c0e709
sha1: c75ca9dad017b6e8b83089fe13dee16f17090e38
sha256: e6a7f146e5a355e832039fe246fcf124f2f2a5eb2471b4a6dced06735c17fa5e
sha512: 8e11ab3bd15aafc25ccf842004236a764c70cff8ce66688cdd6d1922fe21e4926842e72d066de21f1d8be348aa5cb3134e451d49b5e0e8caf0094ec03e4361dd
ssdeep: 6144:8DKW1Lgbdl0TBBvjc/pWqruMPEgbqIBoF1HgvxgF:qh1Lk70TnvjcxWqVrViF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A744CF2032C1C1B3C4AA053585E6CB769E793472076986D7BBDD1B7A2E213E1B6362CD
sha3_384: 49b78588306177b3e988c1f7c2b6e17c567c7609f81eeb662aaa0fc64aa6c447e4dd5648c60eb7023cb3172390110e88
ep_bytes: e8e15c0000e9a4feffff8bff558bec83
timestamp: 2012-07-13 22:47:16

Version Info:

Translation: 0x0000 0x04b0
Comments: SSH, Telnet and Rlogin client
CompanyName: Simon Tatham
FileDescription: SSH, Telnet and Rlogin client
FileVersion: 0.63.0.0
InternalName: Zuenchupu.exe
LegalCopyright: Copyright © 1997-2013 Simon Tatham.
LegalTrademarks:
OriginalFilename: Zuenchupu.exe
ProductName: PuTTY suite
ProductVersion: 0.63.0.0
Assembly Version: 0.63.0.0

Trojan-Downloader.Win32.Agent.xyairi also known as:

CylanceUnsafe
BitDefenderThetaGen:NN.ZexaF.34698.qq1@a4npd6i
CyrenW32/Trojan.DAN.gen!Eldorado
KasperskyTrojan-Downloader.Win32.Agent.xyairi
CynetMalicious (score: 100)
RisingTrojan.Generic@AI.94 (RDMK:cmRtazpHTmXwjUYCbsoJ6RQrWHjh)
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
APEXMalicious
ZoneAlarmTrojan-Downloader.Win32.Agent.xyairi
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Downloader.Win32.Agent.xyairi?

Trojan-Downloader.Win32.Agent.xyairi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment