Worm

Worm:Win32/Xtrat.B!B removal

Malware Removal

The Worm:Win32/Xtrat.B!B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Xtrat.B!B virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Worm:Win32/Xtrat.B!B?


File Info:

name: 5351750633CA6EF76F57.mlw
path: /opt/CAPEv2/storage/binaries/2350eb33c8d0e82081b61357e219dc9ffa317d6dc119db9750b82d37b0c88dca
crc32: CE639843
md5: 5351750633ca6ef76f578253792e9282
sha1: 34de1180ef82db332a87253707f43bfecd21cfe1
sha256: 2350eb33c8d0e82081b61357e219dc9ffa317d6dc119db9750b82d37b0c88dca
sha512: 26678081cd4e47021f5a770977bc21071d70f2c7caf95e98f1a3cde8f087227f282f51ff0a9cef816198183082a62982c882a2eacbbf76b70e28d8335061d272
ssdeep: 3072:P93WNOgc5uu6QEZetkzvJnJT8uUGBd9b2TJOEPOYu:P93RX5qetsvlJ4DGBdu2Yu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163E3F12EA1F0C576D01144FECC5E53D879BBFE3B6C225CAE5EA90DC87D24684940D746
sha3_384: 7c5b2e7ea7fb479d6f142d4b97f8904a0b3f890a1c6939015bc2becfb54316e0c54f59ba94e5690e76bbf7f781951f97
ep_bytes: 558becb9070000006a006a004975f953
timestamp: 2010-12-02 14:57:08

Version Info:

0: [No Data]

Worm:Win32/Xtrat.B!B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Buzus.m3Mc
Elasticmalicious (high confidence)
FireEyeGeneric.mg.5351750633ca6ef7
CAT-QuickHealBackdoor.Xtrat.B9
SkyhighBehavesLike.Win32.Generic.cc
SangforTrojan.Win32.Save.a
K7AntiVirusHacktool ( 005289991 )
K7GWHacktool ( 005289991 )
Cybereasonmalicious.0ef82d
VirITTrojan.Win32.Sasfis.BVDF
SymantecW32.Extrat
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.V
APEXMalicious
KasperskyBackdoor.Win32.Androm.jxcj
AlibabaWorm:Win32/Xtrat.b48e2c62
NANO-AntivirusTrojan.Win32.Buzus.dqgfpj
ViRobotTrojan.Win32.A.Buzus.356611
RisingTrojan.Generic@AI.100 (RDML:awgFffXt3EdWmp0hmMvQKA)
SophosMal/Behav-328
DrWebTrojan.Siggen4.16710
ZillyaTrojan.Buzus.Win32.93887
Trapminesuspicious.low.ml.score
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bnho
WebrootW32.Malware.Gen
GoogleDetected
VaristW32/Helpud.A!Generic
Antiy-AVLTrojan/Win32.Buzus
KingsoftWin32.HeurC.KVMH017.a
MicrosoftWorm:Win32/Xtrat.B!B
XcitiumMalware@#28etxa2w0djlm
ZoneAlarmBackdoor.Win32.Androm.jxcj
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R5273
McAfeeGenericRXCT-FM!5351750633CA
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Androm
Cylanceunsafe
PandaGeneric Malware
TencentMalware.Win32.Gencirc.10b497a7
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.3551344.susgen
FortinetW32/Buzus.GQ!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Xtrat.B!B?

Worm:Win32/Xtrat.B!B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment