Trojan

About “Trojan.Win32.Khalesi.ixgg” infection

Malware Removal

The Trojan.Win32.Khalesi.ixgg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Khalesi.ixgg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Khalesi.ixgg?


File Info:

name: 3F884FC6737C1ECBB50A.mlw
path: /opt/CAPEv2/storage/binaries/ced1dda05872d732c888cc9ae62414192dab44644c88518335f596298f5bdd39
crc32: 59CCF0F2
md5: 3f884fc6737c1ecbb50a87fe27f80a4f
sha1: 1daa36216395523e91b6f3675d0f01a3f0ac4d23
sha256: ced1dda05872d732c888cc9ae62414192dab44644c88518335f596298f5bdd39
sha512: 2299d08825091fe6a537884600e8b8ac9cd97d60bbc21d76818eba1291cfa95d6e9c4e89063d41abb26ac24608f22755b7eada52d417afe89eba8ec81662c114
ssdeep: 3072:/gNDVeONJDpJ/r1azjxm01W7YCQGkJ1RqEznAjXmrNpfN+1TaHTTvFIuZ+5Hi1DC:UrzD/sPX/hrqu3R75ZAHi95b2yy98S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B342392A35B50AEFAC15B38924C44CDE5BD1B0325FBC529BFA20C653FBF8556181B38
sha3_384: 88703328adbd4914e4924778e2127efc158ce6d915809d4d477497673291457127bb0cb385ffbbe51b710aa4638334a6
ep_bytes: 68000000005e83ec04893c2409d24181
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Khalesi.ixgg also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Razy.969191
FireEyeGeneric.mg.3f884fc6737c1ecb
ALYacGen:Variant.Razy.969191
CylanceUnsafe
ZillyaTrojan.Khalesi.Win32.34682
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056e8c71 )
AlibabaTrojan:Win32/Khalesi.b0190da6
K7GWTrojan ( 0056e8c71 )
Cybereasonmalicious.6737c1
BitDefenderThetaAI:Packer.854820031E
CyrenW32/Kryptik.CWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.FFP
Paloaltogeneric.ml
KasperskyTrojan.Win32.Khalesi.ixgg
BitDefenderGen:Variant.Razy.969191
NANO-AntivirusTrojan.Win32.Kryptik.ivvxfc
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Khalesi.Ncnw
Ad-AwareGen:Variant.Razy.969191
SophosML/PE-A + Troj/Agent-BGUD
VIPREGen:Variant.Razy.969191
McAfee-GW-EditionBehavesLike.Win32.VirRansom.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.969191 (B)
IkarusTrojan.Crypt
GDataGen:Variant.Razy.969191
JiangminTrojanDropper.Agent.glwz
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.50E8
ArcabitTrojan.Razy.DEC9E7
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R373212
Acronissuspicious
McAfeeGenericRXAA-FA!3F884FC6737C
VBA32BScope.Trojan.Wacatac
MalwarebytesMachineLearning/Anomalous.95%
APEXMalicious
RisingTrojan.Injector!1.D22B (CLASSIC)
YandexTrojan.Khalesi!eFd1gcxM6m4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FFP!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Khalesi.ixgg?

Trojan.Win32.Khalesi.ixgg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment