Trojan

Trojan.Win32.Agent.xamzxb removal tips

Malware Removal

The Trojan.Win32.Agent.xamzxb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xamzxb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xamzxb?


File Info:

name: 060D0E7D1866829D4F8B.mlw
path: /opt/CAPEv2/storage/binaries/7e507c9aa98d2373ec8e4342184da22f260d72526eadf8e436dcb1fd706ce242
crc32: E15B7C23
md5: 060d0e7d1866829d4f8b2c89a9fd02d0
sha1: 7896c3ab2b3827ee4db4116bd2ca02c0098854d4
sha256: 7e507c9aa98d2373ec8e4342184da22f260d72526eadf8e436dcb1fd706ce242
sha512: 94292b023c2dc5a5bc775041d5471b6c62d0abcd8f29c29de8bc612c7880ba789b36cc0b28c8311f63b0bc45cf57faeda166c50807d5735a3699e0812f49aff9
ssdeep: 12288:FYeXCcsXwfwxcZ1o2YknznU+amR25aqsU36g2bzhVFxy9wxIYH8/e:FYeXHQk+eL3x2YqsU36fC9wGYc2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A7C423A5CA1F81F9E8B642B11D72604F7330AC8435488F31A548972944F7A7B7B7F366
sha3_384: dec4283bce908199a4b81581d28c70949d62648a66299bcbae05d64bdd13b7b5d7912b1aba09e9b3537d61e5c94b7236
ep_bytes: 60e9a2de03008d049357e95af8ffff05
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Win32.Agent.xamzxb also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.30562
FireEyeGeneric.mg.060d0e7d1866829d
McAfeeGenericRXRK-EV!060D0E7D1866
CylanceUnsafe
ZillyaTrojan.VMProtect.Win32.57682
SangforTrojan.Win32.Convagent.gen
K7AntiVirusTrojan ( 0057e5351 )
AlibabaPacked:Win32/VMProtect.0841f0dc
K7GWTrojan ( 0057e5351 )
Cybereasonmalicious.d18668
CyrenW32/VMProtect.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.WV
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.xamzxb
BitDefenderGen:Variant.Doina.30562
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10cff5ad
Ad-AwareGen:Variant.Doina.30562
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PB122
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftGen:Variant.Doina.30562 (B)
IkarusTrojan.Win32.VMProtect
GDataGen:Variant.Doina.30562
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.3501F21
GridinsoftRansom.Win32.Sabsik.oa!s8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
TACHYONTrojan/W32.Convagent.551775
AhnLab-V3Trojan/Win.Generic.C4899751
BitDefenderThetaGen:NN.ZexaF.34212.HKZ@a44fQJkc
ALYacGen:Variant.Doina.30562
MAXmalware (ai score=86)
VBA32BScope.Trojan.Woreflint
MalwarebytesMalware.AI.248678543
TrendMicro-HouseCallTROJ_GEN.R002C0PB122
RisingTrojan.Convagent!8.12323 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VMProtect.WV!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Agent.xamzxb?

Trojan.Win32.Agent.xamzxb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment