Trojan Worm

Trojan:Win32/XWormRAT.A!MTB removal

Malware Removal

The Trojan:Win32/XWormRAT.A!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/XWormRAT.A!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Faeroese
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/XWormRAT.A!MTB?


File Info:

name: 866BB3B21510E4827DB1.mlw
path: /opt/CAPEv2/storage/binaries/1039d40b4a2bc899a54b2f9262db723bac1edf21adef624b4e1ac3fb232b0bff
crc32: 15D850AC
md5: 866bb3b21510e4827db1905c51440153
sha1: 43a54a0e60dee528ce8d8a88f74fa84823e65bfa
sha256: 1039d40b4a2bc899a54b2f9262db723bac1edf21adef624b4e1ac3fb232b0bff
sha512: 1ae20d3957ae9f2ae75ccbda673ec4cbaf34a72ca5d559f11bf332b9a6efb5845de4343f7c8b4d654bdde7aa079c3089a89f6c8dba0bf882549377f05cdc667c
ssdeep: 24576:2r6Lw9Z7L29Wsi5+Sbicn0WeK+obNFFkG:2r60nn75N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D057A02B9999D56E08236F99903DDBC10790CF80819ED07A5F9FE872BF059BCF2661D
sha3_384: a3bd317be17b8b51245e74c3d9679ba8ec2af64423a5854409dbb7ac32b9460cef3a34a44c9b15bad0e016b357ab725c
ep_bytes: 6858994000e8eeffffff000000000000
timestamp: 2015-03-13 15:05:51

Version Info:

0: [No Data]

Trojan:Win32/XWormRAT.A!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
AVGWin32:VBCrypt-DCI [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.130592
FireEyeGeneric.mg.866bb3b21510e482
SkyhighBehavesLike.Win32.Generic.cm
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
Cybereasonmalicious.21510e
BitDefenderThetaGen:NN.ZevbaF.36802.1qZ@aqB4LifO
VirITTrojan.Win32.Generic.HZA
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.BWUV
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:VBCrypt-DCI [Trj]
ClamAVWin.Malware.Generic-7433035-0
KasperskyTrojan.Win32.Agent.apfrs
BitDefenderGen:Variant.Barys.130592
TencentWin32.Trojan.Agent.Gjgl
EmsisoftGen:Variant.Barys.130592 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Barys.130592
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusVirus.Win32.Virut
JiangminTrojan/Agent.iekn
VaristW32/VBInject.AKU.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Agent
MicrosoftTrojan:Win32/XWormRAT.A!MTB
ArcabitTrojan.Barys.D1FE20
ZoneAlarmTrojan.Win32.Agent.apfrs
GDataGen:Variant.Barys.130592
GoogleDetected
AhnLab-V3Trojan/Win.Inject.R641475
VBA32TScope.Trojan.VB
ALYacGen:Variant.Barys.130592
MalwarebytesMalware.AI.1513591827
RisingTrojan.XWormRAT!8.17955 (TFE:3:kySUwm2n1KK)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CBAD!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[dropper]:Win/XWormRAT.A!MTB

How to remove Trojan:Win32/XWormRAT.A!MTB?

Trojan:Win32/XWormRAT.A!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment