Trojan

Trojan.Win32.Agent.xaiauw removal instruction

Malware Removal

The Trojan.Win32.Agent.xaiauw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaiauw virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xaiauw?


File Info:

crc32: 90B535F3
md5: 93f7f58e5ca2777cb2b32d254e611e51
name: 93F7F58E5CA2777CB2B32D254E611E51.mlw
sha1: 568489174d2c80fec95aa11a0d28ea065bc85260
sha256: de3292924ba69a7f7dfd5b6687d6c774a7aecf8e2ac1368d30ce81c61a14e73f
sha512: ba396ffb007067d2720dcfdc7be0dbb47cafafedba121d049f6b044885cc0b6e593202ecc85655e65d295c996683145f2f9ed186a170c84e319135bc3c37d1df
ssdeep: 3072:hDxaVzwmg4CSW8JSuQbJ8SSdzc1rHzoPKZIMIjO/45bb83kGHn:xMm4CCAJP+ETWGIMZ/KH83LHn
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan.Win32.Agent.xaiauw also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057f1701 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.21240
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.46599475
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Injector.af04672c
K7GWTrojan ( 0057f1701 )
Cybereasonmalicious.e5ca27
CyrenW32/Injector.AIY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
KasperskyTrojan.Win32.Agent.xaiauw
BitDefenderTrojan.GenericKD.46599475
MicroWorld-eScanTrojan.GenericKD.46599475
Ad-AwareTrojan.GenericKD.46599475
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.fngpv@0
McAfee-GW-EditionBehavesLike.Win32.Vopak.cc
FireEyeGeneric.mg.93f7f58e5ca2777c
EmsisoftTrojan.GenericKD.46599475 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1141442
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Lokibot.PRF!MTB
GDataWin32.Trojan.Agent.6XQ1HT
AhnLab-V3Trojan/Win.Generic.R430091
McAfeeArtemis!93F7F58E5CA2
MAXmalware (ai score=82)
PandaTrj/CI.A
IkarusTrojan.Win32.Injector
FortinetW32/Injector.EOZI!tr
AVGWin32:InjectorX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Inject.HyoDdjAA

How to remove Trojan.Win32.Agent.xaiauw?

Trojan.Win32.Agent.xaiauw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment