Trojan

Trojan.Win32.Agent.xaherm removal

Malware Removal

The Trojan.Win32.Agent.xaherm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaherm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Turkish
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xaherm?


File Info:

crc32: 5171DE9B
md5: ad9202ed6c4f898434c1a7bae1f3394b
name: AD9202ED6C4F898434C1A7BAE1F3394B.mlw
sha1: 7c4293ccfc64e544c8c1da2278aab62dc0d1ec57
sha256: 2a4bad1e2e460acb41d0a95be49bbceb51df47897e6ec01bd3c5ea106f889563
sha512: 5c3038dca3d85c42f5fd7cb78b4767f9ef00354045510a87e85c9194019cac953929e13ce53c0e35e0c3686679c686abc3b49f868b50fca573c0908cca030355
ssdeep: 6144:sqJeTNBJbjVT+Z7eXqSe6208srGfBA/gR3MMMMiMM+Oz:stTNzbj1a7eXq76WsrSBA/gBMMMMiMM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: calimatimodunador.exe
FileVersions: 7.0.2.54
LegalCopyrights: Vsekdar
ProductVersions: 7.0.21.45
Translation: 0x0129 0x04ea

Trojan.Win32.Agent.xaherm also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057930b1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.62683
CynetMalicious (score: 100)
ALYacGen:Variant.Midie.80001
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/ArkeiStealer.0d8dd79f
K7GWTrojan ( 0057930b1 )
CyrenW32/Kryptik.DPT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HJYA
APEXMalicious
AvastWin32:BotX-gen [Trj]
KasperskyTrojan.Win32.Agent.xaherm
BitDefenderTrojan.GenericKD.45897872
MicroWorld-eScanTrojan.GenericKD.45897872
TencentWin32.Trojan.Agent.Lpuw
Ad-AwareTrojan.GenericKD.45897872
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34628.sq0@ay6xKMiG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.GLUPTEBA.THCAFBA
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.ad9202ed6c4f8984
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
AviraTR/Kryptik.fxnpm
eGambitUnsafe.AI_Score_87%
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftTrojan:Win32/ArkeiStealer.RM!MTB
GDataTrojan.GenericKD.45897872
AhnLab-V3Trojan/Win.GenKryptik.R371622
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=80)
VBA32Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.GLUPTEBA.THCAFBA
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HwoC6Q8A

How to remove Trojan.Win32.Agent.xaherm?

Trojan.Win32.Agent.xaherm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment