Trojan

Trojan.Win32.Agent.xadirt removal

Malware Removal

The Trojan.Win32.Agent.xadirt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xadirt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Detects SunBelt Sandbox through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings

Related domains:

z.whorecord.xyz
a.tomx.xyz
tldrbox.top

How to determine Trojan.Win32.Agent.xadirt?


File Info:

crc32: 1B1EFBC4
md5: 505738e217507efab531b3673fe15c6b
name: o.exe
sha1: b8f8afa26691d27dcea0db39d0c6f3d55ceafe43
sha256: 6d1f5c0cabbd74c860e94b7355970bc614976f004bd47f75fb373906c788c909
sha512: 9dedd88bec5d8d55b94ecc0aa410add1f7563e03a990470f6c9dc04483a2159df23a2afbe36e496a897793e030c40702461e633b357d137aa5d2c5d19fbc4043
ssdeep: 3072:RBNdPm2FL1LwgPPePRZWJUr8ke4P2VKHBKS6vNA27C9mv3epNGkZwM:3HmWpPGPBIGPAKhd2W9mv7cT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0115 0x007b

Trojan.Win32.Agent.xadirt also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Siggen9.14773
MicroWorld-eScanTrojan.GenericKD.33371034
FireEyeGeneric.mg.505738e217507efa
Qihoo-360Generic/HEUR/QVM20.1.75DD.Malware.Gen
ALYacTrojan.GenericKD.33371034
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33371034
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R020C0PBQ20
F-ProtW32/Emotet.AHU.gen!Eldorado
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan.Win32.Agent.xadirt
AlibabaTrojan:Win32/Starter.ali2000005
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan.Agent.Ssqp
Ad-AwareTrojan.GenericKD.33371034
EmsisoftTrojan.GenericKD.33371034 (B)
ComodoMalware@#2nl1nl9liln3u
F-SecureTrojan.TR/AD.Phorpiex.ymgcn
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.hra
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
CyrenW32/Emotet.AHU.gen!Eldorado
AviraTR/AD.Phorpiex.ymgcn
FortinetW32/GenKryptik.EFAO!tr
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FD339A
ZoneAlarmTrojan.Win32.Agent.xadirt
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.MalPe.R327033
Acronissuspicious
McAfeeRDN/Generic.hra
VBA32Trojan.Wacatac
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBJV
TrendMicro-HouseCallTROJ_GEN.R020C0PBQ20
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_73%
GDataTrojan.GenericKD.33371034
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.26691d
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Agent.xadirt?

Trojan.Win32.Agent.xadirt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment