Malware

How to remove “XML/Agent.AN”?

Malware Removal

The XML/Agent.AN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What XML/Agent.AN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

mr-robot.at.ua

How to determine XML/Agent.AN?


File Info:

crc32: 32EC3931
md5: 710f8469f9d12ffb98a6b471decb4366
name: 710F8469F9D12FFB98A6B471DECB4366.mlw
sha1: ee141db2ff33c4abe8ca840283312c9bc4eae6e7
sha256: bc37daba5bc8089c459e110c41b18a2fe15f6a9ec4ef62853067baff6402a7c5
sha512: 5dd62451692154b405ba6271c4461fa3fe98c264a50e88afadaded86c20ee84291dc1788f90ec8bbc59b2a487180ca513b6ef4e91319c4992f8f82f821c39f7c
ssdeep: 24576:BQ9ol9uoYqY5KiEmVUbfbR6pVQva0INZwUOFd3ydDCLjy0x:BQguXhDAbTEovdIBid3DR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

XML/Agent.AN also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.44664487
CylanceUnsafe
ZillyaDropper.Miner.Win32.620
SangforTrojan.Win32.Zpevdo.B
AlibabaTrojanDropper:Win32/Miner.b4eadd45
Cybereasonmalicious.9f9d12
SymantecML.Attribute.HighConfidence
ESET-NOD32XML/Agent.AN
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Dropper.Win32.Miner.vho
BitDefenderTrojan.GenericKD.44664487
MicroWorld-eScanTrojan.GenericKD.44664487
TencentWin32.Trojan-dropper.Miner.Adat
Ad-AwareTrojan.GenericKD.44664487
SophosMal/Generic-S
McAfee-GW-EditionArtemis
FireEyeTrojan.GenericKD.44664487
EmsisoftTrojan.GenericKD.44664487 (B)
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Zpevdo.B
McAfeeArtemis!710F8469F9D1
MAXmalware (ai score=85)
VBA32TrojanDropper.Miner
RisingTrojan.Generic@ML.93 (RDML:OYa4OSCXnTzBPCXNWVN3ww)
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove XML/Agent.AN?

XML/Agent.AN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment