Trojan

Trojan.Win32.Agent.xaljfs information

Malware Removal

The Trojan.Win32.Agent.xaljfs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaljfs virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Icelandic
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.Win32.Agent.xaljfs?


File Info:

name: 53025BF1387DED77AF10.mlw
path: /opt/CAPEv2/storage/binaries/cca5db385e6fc77d5da106a8f7d5d6a58e24cc3c08bf31376176850bf785497c
crc32: 41C9F975
md5: 53025bf1387ded77af10a77837e2f471
sha1: c17362c46fc815178357453bf5a028923020edf6
sha256: cca5db385e6fc77d5da106a8f7d5d6a58e24cc3c08bf31376176850bf785497c
sha512: 2e1a57f2d0f7f38a14f25570672b7eda85d427dbeae3aa1c814edb2338f54865ca177dca7572a9c28fe2c2763e4b4a2fd8c3fb5012ea69f1321620ec08be69f4
ssdeep: 3072:QPa/Va9t7dmzD6N1v/3UxiC5Uz/sH/SW+hsZVggjcGkNIVqIe52:MaCm/6/vrzY6WRb7ITsqs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19904AED176E1C472CDA239708461BBE04E7BB861D970C54B367813AEEF662C0B6353E6
sha3_384: 78429013f14c05310d6decf1cda6645cf1ef548e7061c46d8f347df1e1d3df2597e25fb28e137490b5ea99401ac4be7b
ep_bytes: e8a3370000e978feffffcccccccccccc
timestamp: 2021-05-15 17:13:35

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 23.54.77.27
Translation: 0x0127 0x046a

Trojan.Win32.Agent.xaljfs also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47633613
FireEyeGeneric.mg.53025bf1387ded77
McAfeeRDN/Smoke Loader
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Azorult.93cd99db
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNQQ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.xaljfs
BitDefenderTrojan.GenericKD.47633613
AvastWin32:Trojan-gen
TencentTrojan-Spy.Win32.Stealer.16000121
Ad-AwareTrojan.GenericKD.47633613
SophosMal/Generic-R + Mal/Agent-AWV
DrWebTrojan.Siggen16.4305
TrendMicroTROJ_GEN.R049C0DLF21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftTrojan.Crypt (A)
IkarusTrojan-Ransom.StopCrypt
GDataWin32.Trojan.BSE.13HWNF8
JiangminTrojan.Agent.dsxy
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Stopcrypt.185856.B
MicrosoftTrojan:Win32/Azorult.RMA!MTB
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R457879
Acronissuspicious
VBA32Malware-Cryptor.2LA.gen
ALYacTrojan.GenericKD.47633613
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R049C0DLF21
RisingTrojan.Generic@ML.94 (RDMK:3LWjrxlKfmaMMZpKAae88Q)
YandexTrojan.Agent!Eo6LWCOPy9A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
BitDefenderThetaGen:NN.ZexaF.34084.lu0@a8ZWl1pG
AVGWin32:Trojan-gen
Cybereasonmalicious.46fc81
PandaTrj/GdSda.A

How to remove Trojan.Win32.Agent.xaljfs?

Trojan.Win32.Agent.xaljfs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment