Trojan

Trojan.Win32.Agent.xaksrc malicious file

Malware Removal

The Trojan.Win32.Agent.xaksrc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaksrc virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Trojan.Win32.Agent.xaksrc?


File Info:

name: 50C5A450B085F7DB3A89.mlw
path: /opt/CAPEv2/storage/binaries/a5577d504698576401bb0b0dde2c56667f7573ed46a7fb9103d75476d9b08404
crc32: 1861A198
md5: 50c5a450b085f7db3a89ff057c3e201a
sha1: c34ef824b6c4e37238ae554451e60b0dc11f791e
sha256: a5577d504698576401bb0b0dde2c56667f7573ed46a7fb9103d75476d9b08404
sha512: 8235c96b90c36971e31bacc462484c5e2a421503e06b81156d91546cc3c75603fb6def54851623fa4499f352ce797b8400eb8242b77aa41933ad9181a3268f36
ssdeep: 12288:XzNB0JfiwSdYSui8zZH94I3H1v1LP2jOGoFtAQinJg/NEMBz9:DNsfiTdYSuVzZH9tH1v1LYMgnJWJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14EE46B32A5600072E6F50A73A83C96303E7CEF382755C9AAD6D4BD1D7EB848567F7212
sha3_384: 5cd48dc449b0641b3654eefcc739cc41f83d36ef52ff479c4d42c348b8b6e6043bd9e61e9a12ed9d1bdff5041a35bc5f
ep_bytes: e83a050000e97afeffffcccccccccc8b
timestamp: 2019-09-17 05:33:38

Version Info:

CompanyName: Ratke-Lebsack Inc
FileDescription: MintCream diet 1.3.7.24
FileVersion: 1.3.7.24
InternalName: setup
LegalCopyright: Copyright 2020 Ratke-Lebsack Inc
OriginalFilename: install.exe
ProductName: MintCream diet 1.3.7.24
ProductVersion: 1.3.7.24
Translation: 0x0409 0x04e4

Trojan.Win32.Agent.xaksrc also known as:

LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanTrojan.GenericKD.38111337
FireEyeTrojan.GenericKD.38111337
CAT-QuickHealTrojan.Agent
McAfeeArtemis!50C5A450B085
AlibabaTrojan:Win32/Generic.d701cecc
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R06BC0WKR21
KasperskyTrojan.Win32.Agent.xaksrc
BitDefenderTrojan.GenericKD.38111337
AvastWin32:Malware-gen
TencentWin32.Trojan.Agent.Svhl
Ad-AwareTrojan.GenericKD.38111337
EmsisoftTrojan.GenericKD.38111337 (B)
TrendMicroTROJ_GEN.R06BC0WKR21
McAfee-GW-EditionBehavesLike.Win32.BadFile.jh
GDataTrojan.GenericKD.38111337
AviraTR/Agent.kbglt
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.D2458869
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
VBA32Trojan.Agent
ALYacTrojan.GenericKD.38111337
MAXmalware (ai score=85)
CylanceUnsafe
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Win32.Agent.xaksrc?

Trojan.Win32.Agent.xaksrc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment