Trojan

Trojan.Win32.Agent.xaddvl (file analysis)

Malware Removal

The Trojan.Win32.Agent.xaddvl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaddvl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Trojan.Win32.Agent.xaddvl?


File Info:

crc32: 30572426
md5: 4feb7a5c9818a81c1ab320edb4555a61
name: 5t6ye0jwwy306402.exe
sha1: b84275b6d076ae72924f00adc1fb012f82218f29
sha256: 0f43014c9da0ba2ae207e06b4657a874e1d90f5537aaeb271ad69df16d286b4c
sha512: be8ea052f2742027f689bc86821e3feec9a005ae60f8279b18e6c318a043d767666212b385175948d1a405736fc0373ea95d8023b5edc5d90125f1accf7d2ac7
ssdeep: 6144:pil8BxssHF5REV9v+RsZ0qLpRCyZ8occQAPR3z3S6yRuG:pil8BjHFfEn3CUpR8o1RWNu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Agent.xaddvl also known as:

DrWebTrojan.Emotet.762
MicroWorld-eScanTrojan.GenericKD.33044099
FireEyeTrojan.GenericKD.33044099
McAfeeEmotet-FQF!4FEB7A5C9818
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
ArcabitTrojan.Generic.D1F83683
TrendMicroTrojanSpy.Win32.EMOTET.SML.hp
CyrenW32/Emotet.AGT.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HAWT
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SML.hp
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Agent.xaddvl
BitDefenderTrojan.GenericKD.33044099
NANO-AntivirusTrojan.Win32.Emotet.gzalru
Paloaltogeneric.ml
Ad-AwareTrojan.GenericKD.33044099
EmsisoftTrojan.GenericKD.33044099 (B)
F-SecureTrojan.TR/AD.Emotet.lkofd
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosTroj/Emotet-CGK
IkarusTrojan-Banker.Emotet
F-ProtW32/Emotet.AGT.gen!Eldorado
AviraTR/AD.Emotet.lkofd
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Emotet.DBH!MTB
Endgamemalicious (high confidence)
ZoneAlarmTrojan.Win32.Agent.xaddvl
GDataTrojan.GenericKD.33044099
AhnLab-V3Malware/Win32.Trojanspy.C3980604
VBA32Trojan.Emotet
ALYacTrojan.GenericKD.33044099
MalwarebytesTrojan.Emotet
APEXMalicious
TencentWin32.Trojan.Agent.Piul
FortinetW32/Emotet.HP!tr
WebrootW32.Trojan.Emotet
AVGWin32:Malware-gen
PandaTrj/Resdec.c
Qihoo-360Win32/Trojan.d63

How to remove Trojan.Win32.Agent.xaddvl?

Trojan.Win32.Agent.xaddvl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment