Trojan

Should I remove “Trojan.Win32.Agent.xabwhq”?

Malware Removal

The Trojan.Win32.Agent.xabwhq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xabwhq virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Agent.xabwhq?


File Info:

crc32: 677EF3C8
md5: 41e840fdb8d2f8d9c83fecf5c6716fe4
name: xserver_download001.exe
sha1: 2c4021ac2376930b464da69b3b341c41b0972534
sha256: d42dd1c5e1fad7248a5d2dd5b98ef8712e34b717b91b1908943f5ba7293f296b
sha512: 770ef7f28d3ffb92c04ffca0a6e7f36c30dd40b8c973afadad9c3bf3ba0bfe661a344ff270b54bdb7bb0d651237a3a1547bc6e1d7533ef7db0d01a6b5fc957f6
ssdeep: 98304:040gejvh4ylcpTRAY6QAtgIIWRzd9kW4ruWMP67foGIA70tsRU6GByaOe1beDEH:048jOyOAY6Ftg2Rzd9B4rfMP6zoO70t
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion:
CompanyName:
ProductName:
ProductVersion:
FileDescription:
OriginalFilename:
Translation: 0x0804 0x04b0

Trojan.Win32.Agent.xabwhq also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.41764827
FireEyeGeneric.mg.41e840fdb8d2f8d9
Qihoo-360HEUR/QVM19.1.D69D.Malware.Gen
McAfeeArtemis!41E840FDB8D2
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.41764827
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34090.@J0@aq2j4Tij
CyrenW32/Trojan.ICVR-7116
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataTrojan.GenericKD.41764827
KasperskyTrojan.Win32.Agent.xabwhq
AlibabaTrojan:Win32/Yantai.0e92d64a
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan.Downloader.Yrcm
Ad-AwareTrojan.GenericKD.41764827
F-SecureTrojan.TR/Crypt.ZPACK.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.41764827 (B)
IkarusTrojan.Crypt
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D27D47DB
ZoneAlarmTrojan.Win32.Agent.xabwhq
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
ALYacTrojan.GenericKD.41764827
VBA32TScope.Malware-Cryptor.SB
MalwarebytesRiskWare.VMProtect
PandaTrj/CI.A
RisingTrojan.Crypto!8.364 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_58%
FortinetW32/PossibleThreat
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.1728101.susgen

How to remove Trojan.Win32.Agent.xabwhq?

Trojan.Win32.Agent.xabwhq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment