Trojan

Trojan.Win32.Agent.xaumhg information

Malware Removal

The Trojan.Win32.Agent.xaumhg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaumhg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Agent.xaumhg?


File Info:

name: ABE61413FA67064870B1.mlw
path: /opt/CAPEv2/storage/binaries/bce22446126bc62ecf56790e489c90564d1ad3e2830da87de5797faa4db51bb0
crc32: 731E9235
md5: abe61413fa67064870b1c791047aeb78
sha1: 7e7d740f9659435a984fd717e733d1ad7cee0fd0
sha256: bce22446126bc62ecf56790e489c90564d1ad3e2830da87de5797faa4db51bb0
sha512: 02f767d34aa27bd65cb04011b0c326e8fdbf044424e68cec65848933dd82f707b3d55bfa8eaa341e61cd3e9be9982da7e70d1da5b31c00a91f617e212b77fe51
ssdeep: 6144:KZy+bnr+ap0yN90QE5RX+8EFvIyZhjAoMyN3FoJM/KNk4:rMrGy90jROvIy5pHoY4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C74E10BE7EC8132E87507718DF602C30637BEA55A74876B234F6D5918B26A0B63177B
sha3_384: 307585699df74b84f61e787bac3bacb4d1f0435f338f21bfa1d6962e34e0d1b24c01ee3cd051a58e862e9b5eb2ee2a13
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

Trojan.Win32.Agent.xaumhg also known as:

LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
ClamAVWin.Packed.Disabler-9987080-0
FireEyeGeneric.mg.abe61413fa670648
McAfeeArtemis!ABE61413FA67
MalwarebytesGeneric.Trojan.Injector.DDS
SangforTrojan.Win32.Disabler.Vbuk
K7AntiVirusTrojan ( 00516fdf1 )
AlibabaTrojan:MSIL/Disabler.a1938c38
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.3fa670
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Agent.xaumhg
AvastWin32:BotX-gen [Trj]
DrWebTrojan.Siggen19.32857
VIPRETrojan.GenericKD.65331035
TrendMicroRansom.Win32.STOP.SMYXDBTB.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneStatic AI – Suspicious SFX
AviraTR/Disabler.wcbhh
Antiy-AVLTrojan/Script.Phonzy
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataWin32.Packed.Kryptik.UMAT4Z
GoogleDetected
AhnLab-V3Trojan/Win.SmokeLoader.C5390764
ALYacTrojan.GenericKD.65331035
TencentTrojan.MSIL.Agent.hg
YandexTrojan.Disabler!G6z7qDxyklM
IkarusTrojan-Banker.UrSnif
FortinetPossibleThreat.ZDS
AVGWin32:BotX-gen [Trj]
PandaTrj/RansomGen.A

How to remove Trojan.Win32.Agent.xaumhg?

Trojan.Win32.Agent.xaumhg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment