Trojan

What is “Trojan.Win32.Agent.xaleyf”?

Malware Removal

The Trojan.Win32.Agent.xaleyf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaleyf virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A HTTP/S link was seen in a script or command line
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable Windows Defender
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Agent.xaleyf?


File Info:

name: 2ED1796703C3689FB119.mlw
path: /opt/CAPEv2/storage/binaries/5d7c2937803e09bc292f2e9502f536991d9bb12cdc9316bd588085bcf61b2f5e
crc32: 0AA958B4
md5: 2ed1796703c3689fb11955aa993bee1f
sha1: 2b0753619454a0523978ecbc410cc27c3b5481a3
sha256: 5d7c2937803e09bc292f2e9502f536991d9bb12cdc9316bd588085bcf61b2f5e
sha512: b23a5c030f25a325988e3536b7a89464a29fa67c3ae3da4c728ce0554aac940a116ee383ca7aa862931fa6e654ee85001456446feb9c7f66390b02544907cf01
ssdeep: 3072:HDPWIZff7cLW7DswVlFjN6GWIeujHT5unwQHITS/:LDoL5ar/WIeujUndITO
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1C7C312B915FC3BE2C27FE9B5C0C5E431C6613F09A2DB18788F16CA09A22BA51C99C557
sha3_384: 383e7b1421a76e61eb7a011acd8b92868fed3a5b9fb21535f22bb5e636ace4fb1cc7ebb31e1b83b924030c6b6c1530bf
ep_bytes: 53565755488d35c529feff488dbe0040
timestamp: 2021-12-05 16:53:50

Version Info:

0: [No Data]

Trojan.Win32.Agent.xaleyf also known as:

BkavW32.QjukimanAA.Trojan
LionicTrojan.Win32.Convagent.4!c
DrWebTrojan.BtcMine.3601
MicroWorld-eScanTrojan.GenericKD.38197067
FireEyeGeneric.mg.2ed1796703c3689f
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058b45a1 )
AlibabaTrojan:Win64/CoinMiner.00786793
K7GWTrojan ( 0058b45a1 )
Cybereasonmalicious.19454a
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win64/CoinMiner.AFP
TrendMicro-HouseCallTROJ_GEN.R011C0PL821
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.xaleyf
BitDefenderTrojan.GenericKD.38197067
NANO-AntivirusTrojan.Win64.CoinMiner.jivzls
AvastWin64:CoinminerX-gen [Trj]
TencentWin32.Trojan.Agent.Hwdd
Ad-AwareTrojan.GenericKD.38197067
SophosMal/Generic-S
ZillyaTrojan.CoinMiner.Win64.6766
TrendMicroTROJ_GEN.R011C0PL821
McAfee-GW-EditionBehavesLike.Win64.Generic.cc
EmsisoftTrojan.GenericKD.38197067 (B)
IkarusTrojan.Win64.CoinMiner
GDataTrojan.GenericKD.38197067
AviraTR/CoinMiner.epakv
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASBOL.C5E3
GridinsoftRansom.Win64.Gen.sa
ArcabitTrojan.Generic.D246D74B
MicrosoftTrojan:Win32/Suloc.A
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Downloader.R144334
ALYacTrojan.GenericKD.38197067
VBA32Trojan.Convagent
MalwarebytesTrojan.BitCoinMiner
APEXMalicious
YandexTrojan.Agent!XWGH/qOEQa8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/Miner
AVGWin64:CoinminerX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Agent.xaleyf?

Trojan.Win32.Agent.xaleyf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment