Trojan

Should I remove “Trojan.Win32.Agent.xanfls”?

Malware Removal

The Trojan.Win32.Agent.xanfls is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xanfls virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments

How to determine Trojan.Win32.Agent.xanfls?


File Info:

name: 4CC68AE2BD300028B71E.mlw
path: /opt/CAPEv2/storage/binaries/5e5d7f682d307f61e88b43e6ebb0697688690549783333f7f5b21060e0449679
crc32: 4E8BED9E
md5: 4cc68ae2bd300028b71e3234fb3db4ae
sha1: 29ea898d8faf75772f7a1968e80d90777bea18ef
sha256: 5e5d7f682d307f61e88b43e6ebb0697688690549783333f7f5b21060e0449679
sha512: d7e939cc2b0d63fb1f359d162b94f142bc616524015fa1fa28e72fb7fe10baaf0e27144a3412cc970b35fac156d9cc7eab6532981fd0667c7cff7db337525b3b
ssdeep: 196608:xb0XjU587A9PZdI+rqa71UZaiDMXSBIxN/CfQCeEar:xb0Xw5CA9Bdbt71UZ0XSBIxFYmr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E6633A0FFF004F7E2A25DB06B4C3F63A3A9A725286181FB7380E41D6F7D5612569847
sha3_384: e3db52f46b9d510b146fc0ec25fb3c4ad8526f9122245bd61d33090dc74740cb938f1dc62064277a9e4505b47ca8b483
ep_bytes: 558bec6aff6898c24100680691410064
timestamp: 2019-02-21 16:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 19.00
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 19.00
Translation: 0x0409 0x04b0

Trojan.Win32.Agent.xanfls also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.40901
MicroWorld-eScanDropped:Trojan.Agent.FTAB
FireEyeDropped:Trojan.Agent.FTAB
CAT-QuickHealTrojanSpy.MSIL
McAfeeArtemis!4CC68AE2BD30
CylanceUnsafe
SangforTrojan.Win32.Agent.xanfls
K7AntiVirusTrojan-Downloader ( 0058c0b81 )
AlibabaTrojanPSW:Win32/Stealer.388b40d7
K7GWTrojan-Downloader ( 0058c0b81 )
BitDefenderThetaGen:NN.ZemsilF.34232.jmW@a0Qrh6b
CyrenW32/MSIL_Troj.CY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0PBC22
Paloaltogeneric.ml
ClamAVWin.Dropper.Pswtool-9857487-0
KasperskyTrojan.Win32.Agent.xanfls
BitDefenderDropped:Trojan.Agent.FTAB
NANO-AntivirusRiskware.Win32.PSWTool.hqsnsl
AvastWin32:DropperX-gen [Drp]
Ad-AwareDropped:Trojan.Agent.FTAB
EmsisoftDropped:Trojan.Agent.FTAB (B)
ComodoApplicUnwnt@#1oskvm236onaf
TrendMicroTROJ_GEN.R002C0PBC22
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-R
eGambitGeneric.Malware
AviraTR/Dldr.Agent.tefxq
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.3526583
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftRansom.Win32.AzorUlt.sa
MicrosoftTrojan:Win32/Azorult.RT!MTB
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
GDataDropped:Trojan.Agent.FTAB
CynetMalicious (score: 100)
VBA32CIL.HeapOverride.Heur
ALYacDropped:Trojan.Agent.FTAB
MalwarebytesTrojan.Downloader
TencentWin32.Trojan.Multiple.Pgxa
IkarusTrojan-Downloader.MSIL.Agent
FortinetMSIL/Agent.JVN!tr.dldr
AVGWin32:DropperX-gen [Drp]
PandaTrj/CI.A

How to remove Trojan.Win32.Agent.xanfls?

Trojan.Win32.Agent.xanfls removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment