Malware

Troj/Xtbl-BE removal tips

Malware Removal

The Troj/Xtbl-BE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Xtbl-BE virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Xtbl-BE?


File Info:

crc32: DCA8F112
md5: 4840a1a57af68f45adfd6ec7e0daed22
name: tmpx5wnd2o8
sha1: 9ab678f10433e17ebd645bd785bd13030453df9b
sha256: 0b5ed93a5da40cec20f414028fab9ada951745455c8e982ff67ac39590b9768a
sha512: 26c366c841b710ab37d4427884d5467aed229ebc6987ff5cbf033e16333cbe7f746889b9d7640c609984d6fe7db84eadf67af71790e32e90e1bec9c85b22989e
ssdeep: 24576:QbSyLtIBYWFkfV0hfPnZBdWGktI7ie8ydTF4EWCz:QfKBlNfPjd1ktOie8y1Fzz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2010 by Acro Software Inc., All Rights Reserved
InternalName: PDF Writer
FileVersion: 2, 7, 7, 1
CompanyName: Acro Software Inc.
LegalTrademarks: PDF Writer
ProductName: PDF Writer Application
ProductVersion: 2, 7, 0, 1
FileDescription: PDF Writer Application
OriginalFilename: PDFWriter.EXE
Translation: 0x0409 0x04b0

Troj/Xtbl-BE also known as:

BkavHW32.Packed.
ClamAVWin.Malware.Emotet-7169098-0
FireEyeGeneric.mg.4840a1a57af68f45
CAT-QuickHealTrojan.GenericRI.S13035554
McAfeeRansomware-GNS!4840A1A57AF6
CylanceUnsafe
ZillyaTrojan.Shade.Win32.865
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
SangforMalware
K7AntiVirusTrojan ( 005419d61 )
AlibabaRansom:Win32/Shade.b0ea5f72
K7GWTrojan ( 005419d61 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
F-ProtW32/Shade.R
SymantecRansom.Troldesh
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.32618798
NANO-AntivirusTrojan.Win32.Encoder.fklzlw
Paloaltogeneric.ml
AegisLabTrojan.Win32.Shade.tpIl
MicroWorld-eScanTrojan.GenericKD.32618798
RisingRansom.Troldesh!8.5D1 (CLOUD)
Endgamemalicious (high confidence)
SophosTroj/Xtbl-BE
ComodoTrojWare.Win32.TrojanProxy.Bunitu.GL@7xwiw9
F-SecureHeuristic.HEUR/AGEN.1111647
DrWebTrojan.Encoder.858
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.EMOTET.SMA
McAfee-GW-EditionRansomware-GNS!4840A1A57AF6
EmsisoftTrojan-Ransom.Shade (A)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.GVPQ-3384
JiangminTrojan.Shade.rw
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1111647
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan[Ransom]/Win32.Shade
MicrosoftRansom:Win32/Troldesh.A
ArcabitTrojan.Generic.D1F1B92E
ViRobotTrojan.Win32.Ransom.1381640
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.32618798
AhnLab-V3Malware/Win32.RL_Generic.R291766
VBA32BScope.Trojan.Packed
ALYacTrojan.Ransom.Shade
MAXmalware (ai score=100)
Ad-AwareTrojan.GenericKD.32618798
ESET-NOD32Win32/Filecoder.Shade.A
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMA
TencentMalware.Win32.Gencirc.10cc9c00
YandexTrojan.Shade!
IkarusTrojan-Ransom.Crypted007
MaxSecureTrojan.Malware.73934690.susgen
FortinetW32/Kryptik.GOUT!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34128.ur1@ama3vtai
AVGWin32:Malware-gen
Cybereasonmalicious.57af68
PandaTrj/CI.A
Qihoo-360Win32/Trojan.Ransom.11e

How to remove Troj/Xtbl-BE?

Troj/Xtbl-BE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment