Trojan

Should I remove “Trojan.Win32.Agent.xampqq”?

Malware Removal

The Trojan.Win32.Agent.xampqq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xampqq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Network activity contains more than one unique useragent.
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Agent.xampqq?


File Info:

name: D063DD021A5E51E6FDE0.mlw
path: /opt/CAPEv2/storage/binaries/28099b59983048f4188a7d103abc35d814d8bca0c24d132da546d3ce4f23f47e
crc32: 8C5ADC7D
md5: d063dd021a5e51e6fde0e7f60794af2a
sha1: 6a11b739df71414ec4aac3db5417da3fa5138aca
sha256: 28099b59983048f4188a7d103abc35d814d8bca0c24d132da546d3ce4f23f47e
sha512: 86b74aa4ee81c4f00f99d1b05e7ab12cc70998d1c1c7cb30731c7cf9018febb08417178302978dede83b5bba61728e6d33c314abdfa5721bbacba6ff90b45291
ssdeep: 196608:xTNo/I99EkYfqKVcr5noudcKJ+GoCozsP/v2g:x2/I9rYSPr5nFd8GojY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154563310FAF980B3D4CE5930D94C56B314F8829E272B85FB7640FA5ABBBD525C329E44
sha3_384: 8eedc23fefaad9993551b1137660613ef91cfdbac18db1d2251af693fc34bb9ee024ee28c8549ab4b3f4aaefcd566b03
ep_bytes: 558bec6aff6898c24100680691410064
timestamp: 2019-02-21 16:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 19.00
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 19.00
Translation: 0x0409 0x04b0

Trojan.Win32.Agent.xampqq also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.7997
MicroWorld-eScanDropped:Trojan.GenericKDZ.81636
FireEyeDropped:Trojan.GenericKDZ.81636
CAT-QuickHealTrojan.Redlinestealer
ALYacDropped:Trojan.GenericKDZ.81636
CylanceUnsafe
SangforTrojan.Win32.Agent.xampqq
K7AntiVirusTrojan ( 0058b7d61 )
AlibabaTrojanSpy:Win32/Stealer.ef20e787
K7GWTrojan ( 0058b7d61 )
Cybereasonmalicious.21a5e5
BitDefenderThetaGen:NN.ZemsilF.34160.Gm0@aeHzfre
CyrenW32/MSIL_Kryptik.FNI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0PAF22
Paloaltogeneric.ml
ClamAVWin.Dropper.Pswtool-9857535-0
KasperskyTrojan.Win32.Agent.xampqq
BitDefenderDropped:Trojan.GenericKDZ.81636
NANO-AntivirusRiskware.Win32.PassView.hmklhx
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Starter!1.D93D (CLOUD)
Ad-AwareDropped:Trojan.GenericKDZ.81636
SophosMal/Generic-S (PUA)
ComodoMalware@#3223rakvbidz1
F-SecureHeuristic.HEUR/AGEN.1209204
TrendMicroTROJ_GEN.R002C0PAF22
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftDropped:Trojan.GenericKDZ.81636 (B)
GDataDropped:Trojan.GenericKDZ.81636
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1211353
MAXmalware (ai score=89)
Antiy-AVLTrojan/MSIL.Kryptik
KingsoftWin32.PSWTroj.Undef.(kcloud)
GridinsoftRansom.Win32.AzorUlt.sa
ArcabitTrojan.Generic.D13EE4
MicrosoftTrojan:MSIL/RedLineStealer.MDA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4918087
McAfeeArtemis!D063DD021A5E
VBA32Trojan.MSIL.RedLine.Heur
MalwarebytesSpyware.RedLineStealer
TencentWin32.Trojan.Multiple.Wopf
YandexTrojan.Packed!2jkb4jJek/0
IkarusTrojan.Win32.Crypt
FortinetMSIL/Kryptik.ADRL!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Agent.xampqq?

Trojan.Win32.Agent.xampqq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment