Trojan

Trojan.Win32.Agent.xaibhr removal tips

Malware Removal

The Trojan.Win32.Agent.xaibhr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaibhr virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xaibhr?


File Info:

crc32: 371249B9
md5: 2fa7450cd3760bbceae8c1d69ac6a483
name: 2FA7450CD3760BBCEAE8C1D69AC6A483.mlw
sha1: ba3d590dd90591c358c980cefc6ffab5472a5943
sha256: b3d36c7ba3e0238d3fbd6198c65d02ab2376287a1617868a8e9f576e8c74c523
sha512: f37508ad5ff8edbed0f9d98b657047969483ad88abda83ac9f8c2e105227d15ee8cf9f6710e97bd5cd6823e45fc86fc8d3e0b20b1a17111216fbd46f7bedf540
ssdeep: 6144:8Mm4CCchQ4VHM/S5sDlYnnM6mcWaLpKfdpk1C3VhL:8Mw1VH6S5s5YnM6mNaNKFpHL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Agent.xaibhr also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057f1c31 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
SangforTrojan.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_80% (W)
K7GWTrojan ( 0057f1c31 )
Cybereasonmalicious.cd3760
CyrenW32/Injector.AJK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPSO
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Agent.xaibhr
BitDefenderTrojan.GenericKD.37226233
MicroWorld-eScanTrojan.GenericKD.37226233
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.37226233
SophosMal/Generic-S
ComodoMalware@#1e4qsxdorgd69
VIPREWin32.Malware!Drop
TrendMicroTROJ_GEN.R002C0WGC21
McAfee-GW-EditionBehavesLike.Win32.AdwareTskLnk.gm
FireEyeGeneric.mg.2fa7450cd3760bbc
EmsisoftTrojan.GenericKD.37226233 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
GDataTrojan.GenericKD.37226233
AhnLab-V3Trojan/Win.Generic.C4546307
McAfeeArtemis!2FA7450CD376
MAXmalware (ai score=100)
MalwarebytesMalware.AI.4081919921
TrendMicro-HouseCallTROJ_GEN.R002H0CGC21
IkarusTrojan.Win32.Injector
FortinetW32/Injector.AFC!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HyoDi1sA

How to remove Trojan.Win32.Agent.xaibhr?

Trojan.Win32.Agent.xaibhr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment