Trojan

TrojanProxy:Win32/Xmiler.C removal

Malware Removal

The TrojanProxy:Win32/Xmiler.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanProxy:Win32/Xmiler.C virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • The sample wrote data to the system hosts file.
  • Collects information to fingerprint the system

How to determine TrojanProxy:Win32/Xmiler.C?


File Info:

name: 371B8FD0F9CD21E4E814.mlw
path: /opt/CAPEv2/storage/binaries/c982ade2e1c363dbbb57eddb969cdbe0f1b74a9dbfd9976440acb390a109b84c
crc32: 4CCB8D78
md5: 371b8fd0f9cd21e4e814950f479b1620
sha1: 4866a26bb96ca9ba67564a98b19d8ac1ae2b3234
sha256: c982ade2e1c363dbbb57eddb969cdbe0f1b74a9dbfd9976440acb390a109b84c
sha512: e5aca2b87787a5e9e13a8779b93e70a8d83876f18e7179d170067889a6e2c89d7969bf09af263105684d00b1a4c9dea2364ce6f44a3a8281dead95b249b8ac62
ssdeep: 1536:sq4y6qfkOQIUS2Jr0hYsaBeLGKvBYgSbxfvgTCzuK:J4iu7RV0hHLzvKtFfvEK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE8302440B7E3C1AE5B13433455A1DBE61FAB1332F29368B48B5686BB479DFC54AC250
sha3_384: c5c0f104132d95dbdb477a80c99cdf3dd6f0e12807d40e071ff98631cdbaed713325d1cf8f321f1b1ba6f7b3a65cf65a
ep_bytes: 60be00f00f018dbe002030ff5783cdff
timestamp: 2006-11-07 22:01:21

Version Info:

0: [No Data]

TrojanProxy:Win32/Xmiler.C also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Spambot.BXD
FireEyeTrojan.Spambot.BXD
ALYacTrojan.Spambot.BXD
Cylanceunsafe
VIPRETrojan.Spambot.BXD
SangforTrojan.Win32.Agent.NBE
K7AntiVirusTrojan ( 0055e3dd1 )
AlibabaTrojan:Win32/Xmiler.e26aab9e
K7GWTrojan ( 0055e3dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.D17CAFE31E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.NBE
APEXMalicious
KasperskyTrojan.Win32.Hosts2.gen
BitDefenderTrojan.Spambot.BXD
NANO-AntivirusTrojan.Win32.Qhost.drckqy
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Dzlw
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.Qhost.45065
ZillyaTrojan.Agent.Win32.557678
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Spambot.BXD (B)
IkarusTrojan.Win32.Agent
GDataTrojan.Spambot.BXD
JiangminTrojanProxy.Xmiler.e
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Crypt.ULPM.Gen
XcitiumTrojWare.Win32.Spammer.DComServ.9@zbadv
ArcabitTrojan.Spambot.BXD
ZoneAlarmTrojan.Win32.Hosts2.gen
MicrosoftTrojanProxy:Win32/Xmiler.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C19854
McAfeeGenericRXAA-FA!371B8FD0F9CD
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1003
PandaGeneric Suspicious
RisingMalware.Undefined!8.C (TFE:5:USqFZ8YDEtU)
YandexTrojan.DR.Spambot.Gen
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1851422.susgen
FortinetW32/Hosts2.NBE!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove TrojanProxy:Win32/Xmiler.C?

TrojanProxy:Win32/Xmiler.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment