Trojan

Trojan.Win32.Agent.xafgxm removal guide

Malware Removal

The Trojan.Win32.Agent.xafgxm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xafgxm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xafgxm?


File Info:

crc32: C351716D
md5: f51331c22b3145d4f9d874b00b2b1d10
name: F51331C22B3145D4F9D874B00B2B1D10.mlw
sha1: c4e949901074b10b6b75e3cfa6773e6ae5f369fe
sha256: 4216f800f1974308bb475952263e2dfb440551f271ae657eb2633062b98264fa
sha512: 0c2618c52ba597096f497596214d8feead6b8e32f5a91238a8e186575cff7779240b0f8651febf31e86fa9a63f4c5a7c53f7920257a582417b952c8609ea5b2a
ssdeep: 3072:0anVRU0+vp9aek/af/blI/aWvuAxY0h08D2Gn:0anA0sfO/anC/aIu0Y0++n
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationzi

Trojan.Win32.Agent.xafgxm also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45227760
FireEyeGeneric.mg.f51331c22b3145d4
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.45227760
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0057560b1 )
BitDefenderTrojan.GenericKD.45227760
K7GWTrojan ( 0057560b1 )
BitDefenderThetaGen:NN.ZexaF.34700.jmGfaGaUu0lc
CyrenW32/Trojan.RROT-7976
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan.Win32.Agent.xafgxm
AlibabaTrojan:Win32/Zenpack.b1c441e1
ViRobotTrojan.Win32.Z.Agent.157184.QO
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
Ad-AwareTrojan.GenericKD.45227760
SophosMal/Generic-S
ComodoMalware@#2nmr7i4fnk2bz
F-SecureTrojan.TR/AD.Behavior.puqfs
DrWebTrojan.Siggen11.56853
TrendMicroTROJ_GEN.R002C0WLT20
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Win32.Krypt
JiangminTrojan.DiskWriter.wa
AviraTR/AD.Behavior.puqfs
MAXmalware (ai score=100)
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftTrojan:Win32/Zenpack.MU!MTB
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Generic.D2B21EF0
ZoneAlarmTrojan.Win32.Agent.xafgxm
GDataTrojan.GenericKD.45227760
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRDN/Generic.dx
VBA32Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILR
TrendMicro-HouseCallTROJ_GEN.R002C0WLT20
TencentWin32.Trojan.Agent.Eaml
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_89%
FortinetW32/Kryptik.HGHW!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.54a

How to remove Trojan.Win32.Agent.xafgxm?

Trojan.Win32.Agent.xafgxm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment