Trojan

Trojan.Win32.Agent.xbncta removal

Malware Removal

The Trojan.Win32.Agent.xbncta is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xbncta virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xbncta?


File Info:

name: 00E32F9D1160CF9DC71F.mlw
path: /opt/CAPEv2/storage/binaries/7a626c3281b23162dba87df063efc97b777378bdcbe1f36f6b0a9ab4d95a0885
crc32: 08F06541
md5: 00e32f9d1160cf9dc71f1285870cd0d6
sha1: 296b55e0c370697311bd7ebc71a8ef541b47acb5
sha256: 7a626c3281b23162dba87df063efc97b777378bdcbe1f36f6b0a9ab4d95a0885
sha512: b5b7e0324325a8643eb6b30fabe17f45ad99791f3d31855f662f35d9099aaf984e0828df39c867c6a66ed279c9facd1f6456e3ef212080473decde2dcb2adeb9
ssdeep: 3072:1btCogIdI05UtbYuPzsjtf8/EChCZapCnmHOxVhqpDBL8lZuMgl2:1b4ow8UtpPojtfpSYEpDd0ZuM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172A494929C64AF45FE16453427A56EBA004E7D2F66E4422C785CFA0B337399730AFD0B
sha3_384: 18286f30d5780cfecc16ef04d552322d34b41730b39855aa231d4d61532e3be0265cc2f88309e2205a718c4e2059d310
ep_bytes: 68e4914200e8eeffffff000000000000
timestamp: 2019-01-19 13:34:56

Version Info:

CompanyName: UEFI
ProductName: Kawaii-Unicorn
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Kawaii-Unicorn
OriginalFilename: Kawaii-Unicorn.exe
Translation: 0x0804 0x04b0

Trojan.Win32.Agent.xbncta also known as:

BkavW32.AIDetectMalware
AVGWin32:WormX-gen [Wrm]
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.94CCEEA9.A.83D522C5
FireEyeGeneric.mg.00e32f9d1160cf9d
CAT-QuickHealTrojan.Fareit
SkyhighBehavesLike.Win32.Generic.gt
McAfeeGenericRXTC-TT!00E32F9D1160
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.94CCEEA9.A.83D522C5
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 0054717e1 )
K7GWP2PWorm ( 0054717e1 )
VirITTrojan.Win32.VBUnicorn.AA
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VBClone.E
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:WormX-gen [Wrm]
ClamAVWin.Packed.Generic-9967832-0
KasperskyTrojan.Win32.Agent.xbncta
BitDefenderGeneric.Dacic.94CCEEA9.A.83D522C5
NANO-AntivirusTrojan.Win32.VB.jownbp
SUPERAntiSpywareTrojan.Agent/Gen-Tedy
TencentTrojan.Win32.VB.ha
EmsisoftGeneric.Dacic.94CCEEA9.A.83D522C5 (B)
F-SecureTrojan.TR/VB.Clone.onkgf
DrWebTrojan.MulDrop20.3145
ZillyaTrojan.VBGen.Win32.1
SophosTroj/VB-KCP
SentinelOneStatic AI – Malicious PE
JiangminTrojan.VB.bmcx
VaristW32/VB.VM.gen!Eldorado
AviraTR/VB.Clone.onkgf
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.VBClone
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Fareit.VB!MTB
ArcabitGeneric.Dacic.94CCEEA9.A.83D522C5
ZoneAlarmTrojan.Win32.Agent.xbncta
GDataWin32.Trojan.PSE.2MPO9B
GoogleDetected
AhnLab-V3Trojan/Win.Fareit.R491598
Acronissuspicious
VBA32SScope.Trojan.VB
ALYacGeneric.Dacic.94CCEEA9.A.83D522C5
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.VBClone!1.B5C7 (CLASSIC)
YandexTrojan.VB!hnWVa79e+7U
IkarusTrojan.Win32.VBClone
FortinetW32/VBClone.D!tr
BitDefenderThetaAI:Packer.2252F6B120
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Agent.xbncta?

Trojan.Win32.Agent.xbncta removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment