Trojan

What is “Trojan.Win32.Agent.xaenrq”?

Malware Removal

The Trojan.Win32.Agent.xaenrq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaenrq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xaenrq?


File Info:

crc32: DCFF32C4
md5: d865c99466454a9ff4c0defef66a0223
name: PPS Ford Payment Receipt.exe
sha1: a056e0fd07a3c3a3ad1481fea682a9ef5c8189f2
sha256: 56f092288a058f47cf4a38c04dac8f8fd19a6ba34039bf7803df8928fe03d630
sha512: 7ad9ff3ff2441a1c86c71e358c2a002fb5658a5b8890633b42c9388b7b9b44c952344fe0a08867cf97c400c43d784f084b9ce50b194034380d061fb42ed2f511
ssdeep: 12288:0IHKkV+TvGxB0uY7BMcF46A9jmP/uhu/yMS08CkntxYRW:0IHKw+zGxBdfmP/UDMS08Ckn3X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: RITESH THAKKAR
InternalName: 1
FileVersion: 1.00
CompanyName: PATEL & PATEL
ProductName: College Management Syste
ProductVersion: 1.00
OriginalFilename: 1.exe

Trojan.Win32.Agent.xaenrq also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34705962
FireEyeGeneric.mg.d865c99466454a9f
McAfeeArtemis!D865C9946645
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusSpyware ( 0056cb291 )
BitDefenderTrojan.GenericKD.34705962
K7GWSpyware ( 0056cb291 )
InvinceaMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34298.jn0@ayayG7ai
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Malware.Generic-9774586-0
KasperskyTrojan.Win32.Agent.xaenrq
AlibabaTrojanSpy:Win32/KeyLogger.f5e9559e
ViRobotTrojan.Win32.Z.Keylogger.1196032
AegisLabTrojan.Win32.KeyLogger.l!c
Ad-AwareTrojan.GenericKD.34705962
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop14.2284
TrendMicroTROJ_GEN.R06BC0WJB20
McAfee-GW-EditionBehavesLike.Win32.Trojan.tm
EmsisoftTrojan.GenericKD.34705962 (B)
SentinelOneDFI – Malicious PE
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Spy]/Win32.KeyLogger
MicrosoftTrojan:Win32/Pynamer.A!ac
ArcabitTrojan.Generic.D211922A
ZoneAlarmTrojan.Win32.Agent.xaenrq
GDataTrojan.GenericKD.34705962
CynetMalicious (score: 85)
VBA32TrojanSpy.Keylogger
ALYacTrojan.Agent.Wacatac
MalwarebytesSpyware.Agent
ESET-NOD32a variant of Win32/Spy.KeyLogger.ODN
TrendMicro-HouseCallTROJ_GEN.R06BC0WJB20
YandexTrojan.Igent.bUAajG.1
IkarusTrojan-Spy.Agent
FortinetW32/KeyLogger.ODN!tr.spy
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Trojan.bed

How to remove Trojan.Win32.Agent.xaenrq?

Trojan.Win32.Agent.xaenrq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment