Click on screenshot to zoom
Danger level 8
Type: Trojans
Common infection symptoms:
  • Installs itself without permissions
  • Connects to the internet without permission
  • Strange toolbar installed without Your permission
  • Annoying Pop-up's
  • Slow Computer


TrojanDownloader:MSIL/Xertob.A is a highly dangerous application, which is capable of infecting your computer with countless malicious programs, and this Trojan will do so by exploiting certain websites to download dangerous software, as it has full access to the Internet. TrojanDownloader:MSIL/Xertob.A is capable of allowing the infiltration of keyloggers, fake antispywares (Win 7 Security 2012, XP Antivirus 2012), worms and various other fraudulent applications that can completely destroy your Windows system and steal your personal information for latent cyber criminals’ intentions. So, is you want to avoid these horrible consequences, remove TrojanDownloader:MSIL/Xertob.A immediately when you detect its existence in your Windows.

TrojanDownloader:MSIL/Xertob.A in an extraordinary Trojan, which has implemented one single malicious file to do all the job, so if you notice svchost.exe file running in your Task Manager, stop whatever you are doing and focus all your attention to this malignant component, which needs to be removed at once. You might have heard about svchost.exe before, because this executable file is a very important, legal file, which is responsible for such Windows services as Automatic Updates, Windows Themes or Windows Firewall. The original file is located under C:\Windows\System32; however, TrojanDownloader:MSIL/Xertob.A’s hackers use this well-known name to hide the cloaked malware svchost.exe, which can be found in the C:\Documents and Settings\[User]\AppData folder.

The malicious file is likely to come via Internet downloads as bundled software, and because this TrojanDownloader:MSIL/Xertob.A component can encrypt itself, you will not even know about its existence! Moreover, it can hide itself in your PC for a long time before an actual attack, and even then you might not realize that your system’s disturbances are caused by svchost.exe or the whole TrojanDownloader:MSIL/Xertob.A, as this infection does not have an interface. Svchost.exe cannot be detected and removed by existing AV tools, and creates a completely new Background service to run unwarranted processes, which makes it impossibly hard to found and remove the Trojan. The file can copy and delete files, create folders, modify runtime policies, add new tasks to the Scheduled Task list, and inject infection’s code to Windows boot-up, so that TrojanDownloader:MSIL/Xertob.A processes would start running immediately when the PC is turned on.

Svchost.exe will change your Windows Security Center settings, and will remove any AV or Firewall tools’ alerts coming up on your screen. Instead, you will be bombarded with fake TrojanDownloader:MSIL/Xertob.A pop-ups and other notifications created by the same malignant file. Through svchost.exe, the Trojan will connect to the Internet and communicate with other systems without your permission, enable phishing attacks, read emails and phone book data. Svchost.exe also can disable your system’s safe mode and modify USB drives to spread the infection beyond your PC borders.

TrojanDownloader:MSIL/Xertob.A is a highly malicious Trojan, which can steal your information without much trouble, and will definitely do so, unless you delete its infectious files immediately. And because this Trojan can hide itself from existing AV tools, make sure to install the newest antivirus and antispyware software, which will be designed to remove TrojanDownloader:MSIL/Xertob.A infection from your Windows.

Download Spyware Removal Tool to Remove* TrojanDownloader:MSIL/Xertob.A
  • Quick & tested solution for TrojanDownloader:MSIL/Xertob.A removal.
  • 100% Free Scan for Windows

How to manually remove TrojanDownloader:MSIL/Xertob.A

Files associated with TrojanDownloader:MSIL/Xertob.A infection:

TrojanDownloader:MSIL/Xertob.A processes to kill:


Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.