Trojan

Trojan.Win32.Agent.xahuyq removal

Malware Removal

The Trojan.Win32.Agent.xahuyq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xahuyq virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xahuyq?


File Info:

name: E4D406F236F3AC8E2D8E.mlw
path: /opt/CAPEv2/storage/binaries/3768242828223b8e26e094193d6bc40486af795e28eb5200c31904927dba43a2
crc32: 1EDC5081
md5: e4d406f236f3ac8e2d8e70510f51d434
sha1: 9d5ff38f6fde896d80786d080ca6b1177b7e582a
sha256: 3768242828223b8e26e094193d6bc40486af795e28eb5200c31904927dba43a2
sha512: 4b382aa1222a6e66e38d6e5f9ff5a5efdb85a23d59b6693943fc5fb0cbf97720005ba8a5f9ee9bb3c3b48d05a55d0d3e07779fd9d2647c2d4835e3ca2eecd46f
ssdeep: 393216:VVjSEDI0Wg/QMEOMJjaKnYR0jdguQg8jKFamCgu2XL:3qqQ3BD5Qd8FL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CAF63307B252C131F89505BA199089A64E3B7D7387FAC0FB5FC73AA99D752F14B32188
sha3_384: b5dc296d9b57d1737d269e376ade198566e210a140ccd286f18cb82539e9e8581c9242b54d67519b922c93e400535c9f
ep_bytes: e8a61d0000e989feffff8bff565733f6
timestamp: 2015-02-09 21:57:00

Version Info:

FileDescription: Setup Application
FileVersion: 1.0.0.0
InternalName: sf_rt
LegalCopyright: Setup © 2020-2021
OriginalFilename: suf_launch.exe
ProductVersion: 0.0.0.0
Translation: 0x0409 0x0000

Trojan.Win32.Agent.xahuyq also known as:

LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanTrojan.GenericKD.37897138
FireEyeTrojan.GenericKD.37897138
ALYacTrojan.GenericKD.37897138
CylanceUnsafe
VIPRETrojan.GenericKD.37897138
SangforTrojan.Win32.Agent.xahuyq
K7AntiVirusTrojan-Downloader ( 005779cd1 )
AlibabaTrojanDownloader:Win32/LUADownloader.05164302
K7GWTrojan-Downloader ( 005779cd1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Indiloadz.M.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Agent.FNS
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.xahuyq
BitDefenderTrojan.GenericKD.37897138
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10ceef69
Ad-AwareTrojan.GenericKD.37897138
EmsisoftTrojan.GenericKD.37897138 (B)
ZillyaTrojan.Agent.Win32.2138709
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
GDataTrojan.GenericKD.37897138
GoogleDetected
AviraTR/AD.LUADownloader.jccce
ZoneAlarmTrojan.Win32.Agent.xahuyq
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R424976
McAfeeArtemis!E4D406F236F3
MAXmalware (ai score=81)
VBA32Trojan.Agent
RisingDownloader.Agent!8.B23 (CLOUD)
IkarusTrojan-Downloader.LUA.Agent
MaxSecureTrojan.Malware.118488893.susgen
FortinetW32/Agent.FNS!tr.dldr
AVGWin32:Trojan-gen
Cybereasonmalicious.f6fde8
PandaTrj/CI.A

How to remove Trojan.Win32.Agent.xahuyq?

Trojan.Win32.Agent.xahuyq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment