Trojan

What is “Trojan:Win32/Xiaoba!A”?

Malware Removal

The Trojan:Win32/Xiaoba!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Xiaoba!A virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Xiaoba!A?


File Info:

name: 44F1BFDB1BE284D22B2D.mlw
path: /opt/CAPEv2/storage/binaries/0bcc6560f504cf035446eb7692c1f59a6c6d409eefecae21d640512fd73ef612
crc32: F7F8CF55
md5: 44f1bfdb1be284d22b2d55f8a51a2a12
sha1: 2368fbb933fde16bd51985ed380b23a3b0c9670a
sha256: 0bcc6560f504cf035446eb7692c1f59a6c6d409eefecae21d640512fd73ef612
sha512: 4a737c7efb73057a1de09bd44d53b353d2002a33b5fb4f3c4617c24a6533cccc1872c14fb807fd64c04845bf14a6352a5c6812381b8aead9b1dd15c4a2bd1db4
ssdeep: 12288:6c9iJafmm2VYK+UNo0RweQfoOcvQbFVLrNfm3HkLNMDbu+yr:yVm2VZQf1bLNm3HkxMDbBy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148B46D03F7D1C0B3DA92067018794B3EAA76FA6927704EDB63986D5D5E727C0583A30B
sha3_384: 90c4aa9da9f16acf8932b525f3f39b7b1fb1c00688784941f275847289203be010ca3686092eaf6d349d1b92430d53ee
ep_bytes: 00000000000000000000000000000000
timestamp: 2008-06-12 07:09:26

Version Info:

0: [No Data]

Trojan:Win32/Xiaoba!A also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.47577202
FireEyeTrojan.GenericKD.47577202
ALYacTrojan.GenericKD.47577202
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 0013bf781 )
K7AntiVirusTrojan ( 0013bf781 )
CyrenW32/Trojan.OFOG-4170
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.OCI
APEXMalicious
ClamAVWin.Trojan.Qhost-160
BitDefenderTrojan.GenericKD.47577202
AvastWin32:Miner-AL [Trj]
TencentWin32.Trojan.Generic.Pezp
Ad-AwareTrojan.GenericKD.47577202
EmsisoftTrojan.GenericKD.47577202 (B)
DrWebJS.Miner.11
TrendMicroTROJ_GEN.R002C0DL621
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Spy.Lineage
GDataTrojan.GenericKD.47577202
JiangminBackdoor/PcClient.jbv
Antiy-AVLTrojan/Generic.ASCommon.192
MicrosoftTrojan:Win32/Xiaoba.gen!A
McAfeeArtemis!44F1BFDB1BE2
MAXmalware (ai score=88)
MalwarebytesMalware.AI.793849284
TrendMicro-HouseCallTROJ_GEN.R002C0DL621
RisingTrojan.Kryptik!1.B3E8 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_82%
FortinetW32/Agent.OCI!worm
AVGWin32:Miner-AL [Trj]
PandaTrj/CI.A
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan:Win32/Xiaoba!A?

Trojan:Win32/Xiaoba!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment