Trojan

About “Trojan.Win32.Agent.xamzhi” infection

Malware Removal

The Trojan.Win32.Agent.xamzhi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xamzhi virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the Azorult malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Agent.xamzhi?


File Info:

name: B66BA5BA11D8D0AF4134.mlw
path: /opt/CAPEv2/storage/binaries/577a2f811cc5cfd9a74b545ac3fc3028f3967d70d10c033ddcd996d3b0f511f6
crc32: 62F5E945
md5: b66ba5ba11d8d0af413413d19af43975
sha1: 717c38cf8ba47a679f6fa742ab0254ba994d215e
sha256: 577a2f811cc5cfd9a74b545ac3fc3028f3967d70d10c033ddcd996d3b0f511f6
sha512: 6d6556642a9fb69529d3ece66456883bf9441fa99141b73ae9b9583daae8c316b7d2b6492506ff7e9d75b2c43df664e3ab8d13db5fa223b005bd0dc3b5e1ec4f
ssdeep: 24576:ru6J33O0c+JY5UZ+XC0kGso6FaI1IXgM6YmenKKSUlmDaGJTA4Pqa6jUvOkQwKYX:Fu0c++OCvkGs9Fap5aLKLkDl+dUvO9Yx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EA5BE41A3DC82A1CE6A4372BA36DB219B777C692634F70E1ED83D7A3E723521518353
sha3_384: 7c0e004c910b4846579ac3f50e19b6954b86b526d8b4189c12df13c98af9b450fb0f0445e65dc3d33d2833cf0396f568
ep_bytes: e8b5d00000e97ffeffffcccccccccccc
timestamp: 2019-03-12 13:38:44

Version Info:

FileDescription: Adobe Download Manager
OriginalFilename: Adobe Download Manager
CompanyName: Adobe Systems Incorporated
FileVersion: ...
LegalCopyright: Copyright 2018 Adobe Incorporated. All rights reserved.
ProductName: Adobe Download Manager
ProductVersion: ...
Translation: 0x0409 0x04b0

Trojan.Win32.Agent.xamzhi also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.944072
FireEyeGeneric.mg.b66ba5ba11d8d0af
CAT-QuickHealTrojan.AutoIt.AitInject.ZZ
ALYacGen:Variant.Graftor.944072
CylanceUnsafe
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.a11d8d
VirITTrojan.Win32.Autoit.FU
CyrenW32/AutoIt.OA.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32MSIL/Spy.Agent.AES
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Miner-7086570-0
KasperskyTrojan.Win32.Agent.xamzhi
BitDefenderGen:Variant.Graftor.944072
NANO-AntivirusTrojan.Win32.Quasar.foekoa
TencentMalware.Win32.Gencirc.10b0d056
Ad-AwareGen:Variant.Graftor.944072
EmsisoftGen:Variant.Graftor.944072 (B)
ComodoBackdoor.Win32.QuasarRAT.A@8m6u7h
DrWebBackDoor.HVNC.15
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_TINCLEX.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosML/PE-A + Mal/AuItInj-A
GDataGen:Variant.Graftor.944072
AviraTR/Spy.Agent.zgvfh
Antiy-AVLTrojan/Generic.ASCommon.151
ArcabitTrojan.Graftor.DE67C8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
Acronissuspicious
McAfeeTrojan-AitInject.ak
MAXmalware (ai score=81)
VBA32Trojan.Autoit.F
MalwarebytesTrojan.MalPack.AutoIt
TrendMicro-HouseCallTSPY_TINCLEX.SM1
RisingBackdoor.XRat!1.D01D (CLASSIC)
YandexTrojan.GenAsa!eJ2W40k2TSg
FortinetW32/Carberp.BU!tr.dldr
BitDefenderThetaGen:NN.ZexaF.34182.zqW@auVdLFh
AVGWin32:PWSX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Agent.xamzhi?

Trojan.Win32.Agent.xamzhi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment