Trojan

Trojan.Xiaohao.3109 removal tips

Malware Removal

The Trojan.Xiaohao.3109 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Xiaohao.3109 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Xiaohao.3109?


File Info:

name: F418EF566860A4FC097F.mlw
path: /opt/CAPEv2/storage/binaries/dc6b1531b2295f04f18c5dbbbc2d783a9f9a009c0cd765e710f5680526da9d65
crc32: 5F0FAAAD
md5: f418ef566860a4fc097fb109c9a68758
sha1: eb1dd3077817f89385199768f74c3491809e5036
sha256: dc6b1531b2295f04f18c5dbbbc2d783a9f9a009c0cd765e710f5680526da9d65
sha512: 56a2c8d6c18e7c2cfb4bd1ce9fbdad4557a96d7dab319270a76d425f6ceb0e6769acba272bb8dc94f1e8a4cc8f8e667dd94884c34a168386d837fec7ca060ef8
ssdeep: 6144:f983iH5qyhBlf7mz4vqCzlx+KVHyCV7+DHplqg/KOrCcfGC4xwfbMJYSuGeHYwNf:F8ef7m0vqCzlx+Kz78VUON0eFP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179256202A3E44156F1B36A70D9BA7A900B727C756E3AC62EB944711E3DB27C48933737
sha3_384: 40099d8c845a678cf094e889f14bca9ec77eb8363573b19bdee3c560e6464f39f7919681f554ab8cbe7a8d7231ca56f2
ep_bytes: 60be006040008dbe00b0ffff5783cdff
timestamp: 2007-08-11 06:26:03

Version Info:

CompanyName:
FileDescription: XiaoHao Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: XiaoHao
LegalCopyright: 版权所有 (C) 2007
LegalTrademarks:
OriginalFilename: XiaoHao.EXE
ProductName: XiaoHao 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Trojan.Xiaohao.3109 also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Zbot.29
CAT-QuickHealW32.Lilu.B3
McAfeegeneric!bg.fjt
CylanceUnsafe
ZillyaVirus.Lilu.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000005ac1 )
K7GWTrojan ( 000005ac1 )
Cybereasonmalicious.66860a
VirITTrojan.Win32.Agent_r.ARA
CyrenW32/XiaoHao.A.gen!Eldorado
SymantecW32.Hauxi
ESET-NOD32a variant of Win32/Agent.AI
APEXMalicious
ClamAVWin.Trojan.Jilu-1
NANO-AntivirusTrojan.Win32.Jilu.jsted
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
Ad-AwareGen:Variant.Zbot.29
EmsisoftGen:Variant.Zbot.29 (B)
ComodoTrojWare.Win32.Agent.JHA@59gl8d
BitDefenderThetaGen:NN.ZexaF.34114.!mNfaaI0VLpb
VIPRETrojan.Win32.Malware (fs)
TrendMicroPE_XIAHAO.E-O
McAfee-GW-Editiongeneric!bg.fjt
SophosML/PE-A + W32/Hoaix-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Lilu.a
AviraW32/Agent.AI
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASVirus.171
ArcabitTrojan.Zbot.29
ViRobotWin32.Xiaohao.12288
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Xiaohao.3109
MalwarebytesMalware.AI.1955128637
TrendMicro-HouseCallPE_XIAHAO.E-O
TencentWorm.Win32.Xiaohao.a
YandexTrojan.GenAsa!Ig940bsovQ8
IkarusBackdoor.Win32.DKangel
MaxSecureVirus.W32.Lilu.C
FortinetW32/Generic.AC.196571!tr
PandaW32/XiaoHao.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Xiaohao.3109?

Trojan.Xiaohao.3109 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment