Trojan

Trojan.Win32.Agent.xafgxi information

Malware Removal

The Trojan.Win32.Agent.xafgxi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xafgxi virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Agent.xafgxi?


File Info:

crc32: 1964D66B
md5: 0c8e4aa60d747e6cd2b7620d94aa0807
name: 0C8E4AA60D747E6CD2B7620D94AA0807.mlw
sha1: 8160a630e552f81f863f5500d2718b161b268a2f
sha256: 19675bca8b5bd178071602a07aabf48c756f0405afb9611c504d068c9c2fead0
sha512: b4db9f97010738ca64fe34b51cce06eddfcbb5c12fe4bf0599db946874b49e9f14ab56e9b92d67af1d054272573cf06af543358f1ce1229b5a26847e294c6bbd
ssdeep: 3072:easAtzrWLqHvuJTrXOLDCJni1WQ2UKxiiBUpa:easAJWEvuVyLDCJi8Q2UQR
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationzi

Trojan.Win32.Agent.xafgxi also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35910738
FireEyeGeneric.mg.0c8e4aa60d747e6c
CAT-QuickHealTrojan.Agent
Qihoo-360Win32/Trojan.0f8
ALYacTrojan.GenericKD.35910738
CylanceUnsafe
AegisLabTrojan.Win32.Agent.4!c
SangforMalware
K7AntiVirusTrojan ( 0057560b1 )
BitDefenderTrojan.GenericKD.35910738
K7GWTrojan ( 0057560b1 )
CyrenW32/Trojan.FPYK-3744
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan.Win32.Agent.xafgxi
AlibabaTrojan:Win32/Zenpack.b28d07d0
ViRobotTrojan.Win32.Z.Agent.158208.VA
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
Ad-AwareTrojan.GenericKD.35910738
EmsisoftTrojan.Crypt (A)
ComodoMalware@#11sp5h6xoiv9z
F-SecureTrojan.TR/AD.Behavior.hpdmz
DrWebTrojan.Siggen11.56853
TrendMicroTROJ_GEN.R002C0WLT20
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
JiangminTrojan.DiskWriter.wa
AviraTR/AD.Behavior.hpdmz
MAXmalware (ai score=100)
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftTrojan:Win32/Zenpack.MU!MTB
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Generic.D223F452
ZoneAlarmTrojan.Win32.Agent.xafgxi
GDataTrojan.GenericKD.35910738
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRDN/Generic.hbg
VBA32Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILR
TrendMicro-HouseCallTROJ_GEN.R002C0WLT20
TencentWin32.Trojan.Agent.Hpm
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Kryptik.HGHW!tr
BitDefenderThetaGen:NN.ZexaF.34700.jmGfam1AWuoc
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Agent.xafgxi?

Trojan.Win32.Agent.xafgxi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment