Trojan

Trojan.Win32.Agent.xalfnf removal tips

Malware Removal

The Trojan.Win32.Agent.xalfnf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xalfnf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xalfnf?


File Info:

name: B700AB2E19D5F48CDDD4.mlw
path: /opt/CAPEv2/storage/binaries/210f9e7af8731c1dada22f60c5d600b7534a718e5a3da46081017f542983043f
crc32: E13588BB
md5: b700ab2e19d5f48cddd46034daef53dc
sha1: 6208198c625be019657d90e99c3179758db47bc7
sha256: 210f9e7af8731c1dada22f60c5d600b7534a718e5a3da46081017f542983043f
sha512: 74d71070362a57e40dc89bc81e937978e405242f69bd822c625463b7a6fb7830645d48a73b659ab77d2319bbdbc87b764082a33c60b21a9d6ddb1956d48bdf95
ssdeep: 6144:SLH2rO/5jgKhGns79MdJCWwoSaRRcA6w3VTo3eGjGVHRxtUfOcjHjaJWoC+SfvX:S7nBJhGs7R9YTToJjG/3eDaJC+Sf/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1568423D3A6A767FDC9304B70203A1DBD8664E8129ACA07F7FF9065509413742EB19B2F
sha3_384: 6b022ac9732805dec4eb6e9c230fa56d40378e637970b83786e64b4f48a783d7290103e63e0ce9973dd71708cd7d5b2f
ep_bytes: 9c880c24c7042457b16ea068b5202273
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Win32.Agent.xalfnf also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.160809
FireEyeGeneric.mg.b700ab2e19d5f48c
ALYacGen:Variant.Barys.160809
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2581939
K7AntiVirusTrojan ( 0057e5351 )
AlibabaPacked:Win32/VMProtect.2a8a74bc
K7GWTrojan ( 0057e5351 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.A56D02A21F
CyrenW32/VMProtect.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.WV
TrendMicro-HouseCallTROJ_GEN.R002C0WL621
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Agent.xalfnf
BitDefenderGen:Variant.Barys.160809
TencentMalware.Win32.Gencirc.10cf9e4b
Ad-AwareGen:Variant.Barys.160809
EmsisoftGen:Variant.Barys.160809 (B)
TrendMicroTROJ_GEN.R002C0WL621
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosGeneric ML PUA (PUA)
Paloaltogeneric.ml
GDataGen:Variant.Barys.160809
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.34E2852
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4807534
McAfeeGenericRXQZ-VJ!B700AB2E19D5
MAXmalware (ai score=84)
VBA32BScope.Trojan.Woreflint
MalwarebytesMalware.AI.117028373
APEXMalicious
RisingTrojan.Generic@ML.94 (RDMK:kyPZHgawpx5fEy8gOOXytw)
YandexTrojan.Agent!kSZj+AGNq+Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VMProtect.WV!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.e19d5f
PandaTrj/Genetic.gen

How to remove Trojan.Win32.Agent.xalfnf?

Trojan.Win32.Agent.xalfnf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment