Trojan

Trojan.Xloader information

Malware Removal

The Trojan.Xloader is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Xloader virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan.Xloader?


File Info:

name: EA148CF5DE55A7490BD9.mlw
path: /opt/CAPEv2/storage/binaries/3e26cc02d70717e07a5fad9257773db1077896d5598cc2298849ca257157c04b
crc32: 18E44333
md5: ea148cf5de55a7490bd96798a77bb57f
sha1: eb2a3c7bc48156d9f8970a01ba69793609d8777f
sha256: 3e26cc02d70717e07a5fad9257773db1077896d5598cc2298849ca257157c04b
sha512: fa8c27b5a02769f3990a801f132cbadd8f40a7616dd6aad2c0713495ca3d4cc8979628c4dbbe53dbf13a979ae68bda9fd31b6889bcdf45364d4bbb0a016bf0eb
ssdeep: 6144:xC7UoV4t8ehCbB+6mkMtzLjYF0SXQxUtHr0xOn979kcqBNcHWjrXD2Qr4JRWzYNq:xwdBn57CjOGumhhVqa
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11C45239FBF948558FEC08AF18A77F644A94E6277BB4B43D7084412A3BD216E0E7C490D
sha3_384: 81eb7afbf43b0a83358bc95bca23e4df7272697b91fbfbf1c9417ab430677f928bb93b1a5da821dcfdf1322e4285c47c
ep_bytes: ff250020400007000000610000000700
timestamp: 2052-01-01 07:12:24

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: MelvinCapital
FileDescription: bonkersV2
FileVersion: 9.12.3.0
InternalName: bonkersV2.exe
LegalCopyright: Copyright © 2022
LegalTrademarks: MC
OriginalFilename: bonkersV2.exe
ProductName: bonkersV2
ProductVersion: 9.12.3.0
Assembly Version: 9.12.3.0

Trojan.Xloader also known as:

LionicTrojan.MSIL.Noon.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.14322
FireEyeGeneric.mg.ea148cf5de55a749
ALYacIL:Trojan.MSILZilla.14322
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.128046
SangforSpyware.MSIL.Noon.gen
K7AntiVirusTrojan ( 0058cd211 )
AlibabaTrojan:MSIL/GenKryptik.3541b2bc
K7GWTrojan ( 0058cd211 )
BitDefenderThetaGen:NN.ZemsilCO.34182.jn0@aSFf0pb
CyrenW32/MSIL_Kryptik.GJY.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.KEG
TrendMicro-HouseCallTROJ_GEN.R06FC0WAO22
Paloaltogeneric.ml
ClamAVWin.Packed.Lazy-9937692-0
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderIL:Trojan.MSILZilla.14322
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-downloader.Agent.Ajlc
SophosMal/Generic-S
ComodoMalware@#2wl6wi80twew6
F-SecureTrojan.TR/Kryptik.hxxvh
DrWebTrojan.DownLoader44.35357
TrendMicroTROJ_GEN.R06FC0WAO22
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Suspicious PE
EmsisoftIL:Trojan.MSILZilla.14322 (B)
APEXMalicious
AviraTR/Kryptik.hxxvh
Antiy-AVLTrojan/MSIL.GenKryptik
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
GDataIL:Trojan.MSILZilla.14322
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Sabsik.C4933096
McAfeeArtemis!EA148CF5DE55
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Xloader
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL:YrD4ACEq3Ps5MMJtSZSoyA)
YandexTrojan.GenKryptik!d5sY/cyf/UU
IkarusTrojan.Inject
MaxSecureTrojan.Malware.73691310.susgen
FortinetMSIL/GenKryptik.FPUC!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Xloader?

Trojan.Xloader removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment