Trojan

Trojan.Win32.Agent.xaisub removal tips

Malware Removal

The Trojan.Win32.Agent.xaisub is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaisub virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Agent.xaisub?


File Info:

crc32: DB93ACB3
md5: 448f83467c61e465162daf7cf8d9e88f
name: 448F83467C61E465162DAF7CF8D9E88F.mlw
sha1: c627061336905606c2c26b2b460ac4246fd54ca5
sha256: 4773c7c5c52d0163bfa32cb271399692831e00ff7e6877f0877091e111c9f063
sha512: 1f72e8cc6ec0c5d8f82a47ccd0e8dfa91bb9e7e90a00b34a6a466c8823579e58330f4c709ecb6c580814c3875bf618c1cbb7a5c83f70e8be08dbe46ca1a41fe3
ssdeep: 1536:5EBupM4lApP843c9C72xMDqXq39T8g9AhfIRorEjc145:g4+p04s9iGMDfl0PrEw145
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0414 0x04b0
InternalName: Blankningscu5
FileVersion: 1.00
CompanyName: Asus
Comments: Thunderbird
ProductName: spicevpn.com
ProductVersion: 1.00
FileDescription: Hp, Inc.
OriginalFilename: Blankningscu5.exe

Trojan.Win32.Agent.xaisub also known as:

K7AntiVirusTrojan ( 005825981 )
LionicTrojan.Win32.Mucc.4!c
Elasticmalicious (high confidence)
ALYacTrojan.GenericKD.37585152
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.37585152
K7GWTrojan ( 005825981 )
Cybereasonmalicious.336905
CyrenW32/VBInject.HO3.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Agent.FCS
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.xaisub
MicroWorld-eScanTrojan.GenericKD.37585152
Ad-AwareTrojan.GenericKD.37585152
SophosMal/Generic-S + Troj/Zbot-PMW
ComodoTrojWare.Win32.UMal.kpapy@0
BitDefenderThetaGen:NN.ZevbaCO.34142.hm0@aCcK5UjO
McAfee-GW-EditionRDN/Mucc
FireEyeGeneric.mg.448f83467c61e465
EmsisoftTrojan.GenericKD.37585152 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
KingsoftWin32.Troj.Undef.(kcloud)
GDataTrojan.GenericKD.37585152
AhnLab-V3Malware/Win.AGEN.C4632970
McAfeeRDN/Mucc
MAXmalware (ai score=82)
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.F063!tr

How to remove Trojan.Win32.Agent.xaisub?

Trojan.Win32.Agent.xaisub removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment