Trojan

How to remove “Trojan.Win32.Agent.xanfip”?

Malware Removal

The Trojan.Win32.Agent.xanfip is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xanfip virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments

How to determine Trojan.Win32.Agent.xanfip?


File Info:

name: ECDE1F6A8B3474174D3A.mlw
path: /opt/CAPEv2/storage/binaries/a98f5694ed54129b8c7e88ca31b55b831d45d368ab9fb95dfed778626e5b3889
crc32: B0BD5F70
md5: ecde1f6a8b3474174d3a7171a533aafe
sha1: af1bad1fded54d2df7191d5fb59eed87cd96c306
sha256: a98f5694ed54129b8c7e88ca31b55b831d45d368ab9fb95dfed778626e5b3889
sha512: 2a3d18e106fc2ae67e832f67130589e1fc139ea51fa93605d9066b7431adf752967f90a0ce638c5c79797d6b2224a0e5ddc771a6081858615b06757e7e9991c1
ssdeep: 196608:JMPpJQ4H16PmVsXHvbdFyAExeVBQ7mGZBORzr:JKQ4HmBHvfyAExerulO1r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115663318F069DAA3D16375325EBA451E03E972960C15721F1382EF6DB9067E3D2CF3A2
sha3_384: 79b2b82ff8fcc9373feb0b432c1cd4334fcec1f976cc90e152dfed681e87d24afa083f485131e0232aa0654fa28ce0dd
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2020-08-01 02:44:18

Version Info:

0: [No Data]

Trojan.Win32.Agent.xanfip also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ecde1f6a8b347417
CAT-QuickHealTrojanpws.Msil
ALYacGen:Variant.Jaik.49613
MalwarebytesGeneric.Malware/Suspicious
AlibabaTrojanSpy:Win32/Stealer.233e0be4
Cybereasonmalicious.a8b347
BitDefenderThetaGen:NN.ZemsilF.34212.jmW@aCA9lEo
CyrenW32/Trojan.RUCE-1393
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Barys-9859263-0
KasperskyTrojan.Win32.Agent.xanfip
BitDefenderGen:Variant.Jaik.49613
NANO-AntivirusRiskware.Win32.PSWTool.hqsnsl
TencentWin32.Trojan.Multiple.Aoti
EmsisoftGen:Variant.Jaik.49613 (B)
ComodoApplicUnwnt@#1oskvm236onaf
DrWebTrojan.PWS.Siggen3.11040
McAfee-GW-EditionBehavesLike.Win32.ICLoader.vc
SophosMal/Agent-AWV
GDataGen:Variant.Jaik.49613
WebrootW32.AGent.Gen
AviraHEUR/AGEN.1210138
Antiy-AVLTrojan/Win32.Generic
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4960336
VBA32CIL.HeapOverride.Heur
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R002H0AB922
RisingDropper.Agent/NSIS!1.D805 (CLASSIC:E0:azfKBk1fj7N)
IkarusTrojan-Downloader.MSIL.Agent
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Agent.JVN!tr.dldr
PandaTrj/CI.A

How to remove Trojan.Win32.Agent.xanfip?

Trojan.Win32.Agent.xanfip removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment