Backdoor Worm

Backdoor.MSIL.XWorm information

Malware Removal

The Backdoor.MSIL.XWorm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.XWorm virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor.MSIL.XWorm?


File Info:

name: 35E466437EB1EBC61C9F.mlw
path: /opt/CAPEv2/storage/binaries/ca2d2050ca141b5498d990b44dc02e65ff472f9503114eb27768cbaec7afe090
crc32: 2188A31F
md5: 35e466437eb1ebc61c9f46ca2bbf5bc8
sha1: e7b0dba3d163156a20a4bd997913f49e9d525394
sha256: ca2d2050ca141b5498d990b44dc02e65ff472f9503114eb27768cbaec7afe090
sha512: e67f4934bc41480d7b8f72995b15c30ec5f67d6778ba937c0be5dc5fc5da260b59f3cfd2f2d41e836c498006f13450daa09e995f4533b0ae4871325d409cad01
ssdeep: 768:l03GCeiX2oTVjjQ24Uu8jEl/CIg9N3hcN1AryOs:l0ZuVUdElJg9fcQLs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143130A8DB7CF1110CBBD77B66AB3A201023165535767EF9E68C405AA2B7BBC049819F3
sha3_384: 0574cff2fe27e70edf08e8357fcc295a79acba3603536e1703bd7d3748e02e0f462bc4673f8ddd5a222b13b69dbc780a
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-06-10 04:28:17

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: XWormbuffed.exe
LegalCopyright:
OriginalFilename: XWormbuffed.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Backdoor.MSIL.XWorm also known as:

BkavW32.AIDetectMalware
ElasticWindows.Trojan.Xworm
DrWebTrojan.MulDrop21.26970
MicroWorld-eScanIL:Trojan.MSILZilla.25629
CAT-QuickHealTrojan.MsilFC.S28836709
McAfeeGenericRXRO-DU!35E466437EB1
Cylanceunsafe
VIPREIL:Trojan.MSILZilla.25629
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.3d1631
BitDefenderThetaGen:NN.ZemsilF.36250.cm0@aCo65Ud
CyrenW32/MSIL_Agent.CDE.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Agent.BTN
APEXMalicious
KasperskyHEUR:Trojan.MSIL.DOTHETUK.gen
BitDefenderIL:Trojan.MSILZilla.25629
AvastWin32:DropperX-gen [Drp]
EmsisoftIL:Trojan.MSILZilla.25629 (B)
F-SecureTrojan:W32/XwormRAT.A
McAfee-GW-EditionBehavesLike.Win32.Generic.pm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.35e466437eb1ebc6
SophosMal/Generic-S
IkarusTrojan.MSIL.XWorm
GDataMSIL.Backdoor.SiRAT.A
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
ArcabitIL:Trojan.MSILZilla.D641D
ZoneAlarmHEUR:Trojan.MSIL.DOTHETUK.gen
MicrosoftBackdoor:MSIL/AsyncRat!atmn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.AntiVm.C4878692
Acronissuspicious
VBA32Backdoor.MSIL.XWorm.gen
ALYacIL:Trojan.MSILZilla.25629
MalwarebytesGeneric.Trojan.MSIL.DDS
PandaTrj/GdSda.A
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BTN!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.MSIL.XWorm?

Backdoor.MSIL.XWorm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment