We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
VirTool:WinNT/Xiaoho
Aliases: Win-Trojan/Rootkit.4224.C (AhnLab) Trojan-Dropper.Win32.Agent.vbl (Kaspersky) TR/Drop.Agent.vbl.10 (Avira) Trojan.MulDrop2.62855 (Dr.Web) Hack.Xiaoho!38C5 (Rising AV)
Summary
VirTool:WinNT/Xiaoho is a kernel-mode driver that stops target processes.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
- Microsoft Security Essentials or, for Windows 8, Windows Defender
- Microsoft Safety Scanner