Trojan

What is “Trojan.Win32.Agent.xahscq”?

Malware Removal

The Trojan.Win32.Agent.xahscq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xahscq virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xahscq?


File Info:

name: 31EF1140DF9CF115B9B3.mlw
path: /opt/CAPEv2/storage/binaries/131e65c339750a0e31364085183e69c8bead07ca9550aeb8ba084eb268c1290c
crc32: 12DAEF56
md5: 31ef1140df9cf115b9b3fcd65805d01f
sha1: 02f4f40b3daa6c22d8788cf0e288ce0655068327
sha256: 131e65c339750a0e31364085183e69c8bead07ca9550aeb8ba084eb268c1290c
sha512: 714696824c493f7496f358efaf16e385d175e2387634670f482ad24cf682d3ed43c27794161df41440dc87fe746ab975ac5e0a0b4cbed9bd676eb0838e6cd24e
ssdeep: 393216:cVjSE1ux/fSTCYOvtlLrU3DriPQ3Gz78iMkG/D0:YokhQUfnW0iGY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138E63383F602C076E8950AB50411EAB54F7A7E329776D0F76BE036165E763E1CA3234E
sha3_384: d65527dcff6f51223b68b81a913b54f6dc8404f036f1aaa59420993edf19e67ead13dd00816b0e65731a7c624cbf780a
ep_bytes: e8a61d0000e989feffff8bff565733f6
timestamp: 2015-02-09 21:57:00

Version Info:

Comments: Created with Setup Factory
FileDescription: Setup Application
FileVersion: 9.5.0.0
InternalName: suf_launch
LegalCopyright: Setup Engine Copyright © 2004-2015 Indigo Rose Corporation
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
OriginalFilename: suf_launch.exe
ProductName: Setup Factory Runtime
ProductVersion: 9.5.0.0
Translation: 0x0409 0x04e4

Trojan.Win32.Agent.xahscq also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46368402
FireEyeTrojan.GenericKD.46368402
McAfeeArtemis!31EF1140DF9C
CylanceUnsafe
SangforTrojan.Win32.Agent.xahscq
K7AntiVirusTrojan-Downloader ( 005779501 )
AlibabaTrojanDownloader:Win32/Generic.9d564c3d
K7GWTrojan-Downloader ( 005779501 )
Cybereasonmalicious.b3daa6
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/TrojanDownloader.Agent.FNS
KasperskyTrojan.Win32.Agent.xahscq
BitDefenderTrojan.GenericKD.46368402
AvastWin32:Trojan-gen
TencentWin32.Trojan-Downloader.Oader.Jjgl
Ad-AwareTrojan.GenericKD.46368402
EmsisoftTrojan.GenericKD.46368402 (B)
DrWebTrojan.PWS.Stealer.31026
VIPRETrojan.GenericKD.46368402
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
APEXMalicious
GDataTrojan.GenericKD.46368402
WebrootW32.Trojan.Gen
AviraTR/Dldr.Agent.bftlw
Antiy-AVLTrojan/Generic.ASSuf.4C40A
KingsoftWin32.Troj.Agent.(kcloud)
ArcabitTrojan.Generic.D2C38692
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacTrojan.GenericKD.46368402
MAXmalware (ai score=89)
RisingDownloader.Agent!8.B23 (CLOUD)
IkarusTrojan-Downloader.LUA.Agent
FortinetW32/Agent.FNS!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Trojan.Win32.Agent.xahscq?

Trojan.Win32.Agent.xahscq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment