Trojan

Trojan.Win32.Agent.xbgmpw information

Malware Removal

The Trojan.Win32.Agent.xbgmpw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xbgmpw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xbgmpw?


File Info:

name: 21FD5A61CD44739CBC79.mlw
path: /opt/CAPEv2/storage/binaries/46123d012075cca8b6fecd1ca0a528f4fc904cf9c6220ae0173af1d0c93fad5b
crc32: E27361EE
md5: 21fd5a61cd44739cbc7995776253a625
sha1: 8c432abc6c0ffae34534d6d492404226245d8f87
sha256: 46123d012075cca8b6fecd1ca0a528f4fc904cf9c6220ae0173af1d0c93fad5b
sha512: 7d6fd63d834f9b3c7c18842159cb9923713a9ac5a970b7ba932ec0571f4963ae793dbddb08a7b1dc1102d401118994b49b882a7c6058919c44fb74b137538860
ssdeep: 3072:r4J6lA7sKLq7drXtWB38hGmHlvMqnwiuN:r497yhrXa8EmHlEqnwiu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9048F628970BB13E951093517E06BFB801D3C2F4BE5060A7CADDA5F3763D9A349FA42
sha3_384: 1b59f90b5c3525e3d6d4b452cb35acc412c9308d3ece050bcceab8b53af626766393025349abb9f1067d3670c8cc21c5
ep_bytes: 68c0914200e8f0ffffffcd0000000000
timestamp: 2019-04-26 10:28:09

Version Info:

0: [No Data]

Trojan.Win32.Agent.xbgmpw also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.tsbh
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.94CCEEA9.A.B2226F8C
FireEyeGeneric.mg.21fd5a61cd44739c
CAT-QuickHealTrojan.MuldVMF.S21469993
SkyhighBehavesLike.Win32.Generic.ct
McAfeeGenericRXHA-ZI!21FD5A61CD44
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 00581a9e1 )
VaristW32/VB_Troj.J.gen!Eldorado
K7GWP2PWorm ( 00581a9e1 )
Cybereasonmalicious.1cd447
BitDefenderThetaAI:Packer.A43D1AC31F
VirITTrojan.Win32.VBUCornT.DRP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FNGV
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R03BC0DL723
AvastWin32:VB-AJKU [Trj]
ClamAVWin.Malware.Generickdz-10004857-0
KasperskyTrojan.Win32.Agent.xbgmpw
AlibabaTrojan:Win32/Muldrop.329
NANO-AntivirusTrojan.Win32.Banker1.fnwqkb
RisingTrojan.VBClone!1.E032 (CLASSIC)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
ZillyaTrojan.GenKryptik.Win32.352106
TrendMicroTROJ_GEN.R03BC0DL723
SophosMal/VB-AQT
IkarusTrojan.Crypt
JiangminTrojan.VB.aqyg
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.Wacatac.b
KingsoftWin32.Trojan.Agent.pef
XcitiumMalware@#3cvts83sz4hbs
MicrosoftTrojanDropper:Win32/Muldrop!pz
ZoneAlarmTrojan.Win32.Agent.xbgmpw
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R603325
Acronissuspicious
VBA32SScope.Trojan.VB
TACHYONTrojan/W32.VB-Agent.188435.F
Cylanceunsafe
PandaTrj/Chgt.AC
TencentTrojan.Win32.VB.ko
YandexTrojan.Agent!X1Ps5qmRiuI
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.GenericML.xnet
FortinetW32/VBClone.D!tr
AVGWin32:VB-AJKU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan:Win/Generic.CW(dyn)

How to remove Trojan.Win32.Agent.xbgmpw?

Trojan.Win32.Agent.xbgmpw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment