Trojan

What is “Trojan.Win32.Agent.xamysb”?

Malware Removal

The Trojan.Win32.Agent.xamysb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xamysb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments

How to determine Trojan.Win32.Agent.xamysb?


File Info:

name: 07175643B778B75D2AF7.mlw
path: /opt/CAPEv2/storage/binaries/88b46678a6fe4582fab7cfa52e87bdb30c77dfcf78e782cb67e80556377e6a59
crc32: A98E05F1
md5: 07175643b778b75d2af78b292ea08dbb
sha1: a65c603ddd79fa5ea264ca90bea2087b1495fea1
sha256: 88b46678a6fe4582fab7cfa52e87bdb30c77dfcf78e782cb67e80556377e6a59
sha512: caabeff131d17e3eb6262c94199224ddd290c78722f5e77d06afeea571f291dec82c94b1754954ac02cc85086aba6c63315188c8d4858cd8ab19a022d2478d37
ssdeep: 196608:JN7vD+cPykYOBdukJleKPEn/fqoDt9EtA2iFh:JRvD+cPPfRJleK8n/f/t9Eit
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E7633C90B00F2F3D5215871297BC5B74799903A6C1E4BD5FA280983FB6C88967A77B3
sha3_384: a7c8ada679c7fb8f2a2da5a20b48991da03c13e16d55c40c22cd2bca8d021acac3566a36ca0c51a3fe17e29cdcba3b65
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2020-08-01 02:44:18

Version Info:

0: [No Data]

Trojan.Win32.Agent.xamysb also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.07175643b778b75d
CAT-QuickHealRansom.Stopcrypt
ALYacDropped:Trojan.GenericKD.38794992
BitDefenderDropped:Trojan.GenericKD.38794992
CyrenW32/Qbot.FK.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Pswtool-9857487-0
KasperskyTrojan.Win32.Agent.xamysb
NANO-AntivirusRiskware.Win32.PSWTool.hqsnsl
TencentWin32.Trojan.Multiple.Dbb
EmsisoftDropped:Trojan.GenericKD.38794992 (B)
ComodoMalware@#2o8f2q1tb7uai
DrWebTrojan.Siggen16.38471
TrendMicroTROJ_FRS.0NA103AV22
McAfee-GW-EditionBehavesLike.Win32.Emotet.wc
SophosMal/Agent-AWV
AviraHEUR/AGEN.1144141
Antiy-AVLTrojan/Generic.ASMalwS.351994C
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/MereTam.A
ZoneAlarmHEUR:Trojan-Ransom.Win32.Stop.gen
GDataWin32.Trojan.Ilgergop.XP8FJS
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Frs.C4949524
McAfeeArtemis!07175643B778
MAXmalware (ai score=80)
VBA32BScope.Exploit.ShellCode
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103AV22
RisingDropper.Agent/NSIS!1.D805 (CLASSIC:bWQ1OikFY0dkBAIg6ZAnAasSZQo)
FortinetW32/GenKryptik.ETEM!tr
BitDefenderThetaGen:NN.ZexaF.34182.tq0@ai1pzhdG
AVGWin32:Malware-gen
Cybereasonmalicious.3b778b
Paloaltogeneric.ml

How to remove Trojan.Win32.Agent.xamysb?

Trojan.Win32.Agent.xamysb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment