Ransom

What is “Ransom.Xpiro.2”?

Malware Removal

The Ransom.Xpiro.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Xpiro.2 virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Ransom.Xpiro.2?


File Info:

name: 2F4D25323918680F573A.mlw
path: /opt/CAPEv2/storage/binaries/d055b2f4ce8c74b49ecf4e9ca706a58aecd1b24429deaeafc68fba6c8f309cc6
crc32: 697B21B7
md5: 2f4d25323918680f573a368acd4167db
sha1: ab7686a06b9837299b94a532b7bf820104792508
sha256: d055b2f4ce8c74b49ecf4e9ca706a58aecd1b24429deaeafc68fba6c8f309cc6
sha512: 18054524f9af904fa9bdc47247d1f97628a477daf8789a89299889b933df49e3b3aeb50ea37b9107043b9d0374e4baca0779f2e555bfcdb341aa981aa5df8ae3
ssdeep: 384:GBt7Br5xjLMAgA71FbhvUv2OkxN2Okxj/zFd1vqFd1vY6A:W7BlpgpARFbhGUM/zX1vqX1vY6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D83191EDF8A4463F39AA831298EB05C5953C9C1777EADFE62D35CDD4C90DB09A100AB
sha3_384: 2a449350488e4e3c11daec5e9d5809037a2f12eabbc5c035652d7b203e84bf0bd76872fe3dfcdc24d984d327e8eb7471
ep_bytes: 558bec6aff684031400068b022400064
timestamp: 2011-03-15 04:06:07

Version Info:

0: [No Data]

Ransom.Xpiro.2 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Xpiro.2
ClamAVWin.Malware.Generickdz-9938530-0
FireEyeGeneric.mg.2f4d25323918680f
SkyhighBehavesLike.Win32.Generic.mz
McAfeeGenericATG-FAF!2F4D25323918
MalwarebytesMachineLearning/Anomalous.97%
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 000142251 )
K7GWTrojan ( 000142251 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36792.fqZ@aGBV9ui
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.NBJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Cosmu.bwts
BitDefenderGen:Variant.Ransom.Xpiro.2
NANO-AntivirusTrojan.Win32.Cosmu.bgzaxj
SUPERAntiSpywareTrojan.Agent/Gen-Cosmu
AvastWin32:RansomX-gen [Ransom]
TencentTrojan.Win32.Cosmu.we
SophosML/PE-A
DrWebTrojan.Encoder.185
VIPREGen:Variant.Ransom.Xpiro.2
EmsisoftGen:Variant.Ransom.Xpiro.2 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Cosmu.aqq
WebrootW32.Trojan.Gen
GoogleDetected
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Cosmu
Kingsoftmalware.kb.a.994
MicrosoftTrojan:Win32/Zombie!rfn
ArcabitTrojan.Ransom.Xpiro.2
ZoneAlarmTrojan.Win32.Cosmu.bwts
GDataWin32.Trojan.Cosmu.B
VaristW32/Agent.DZF.gen!Eldorado
Acronissuspicious
VBA32Trojan.Cosmu
ALYacGen:Variant.Ransom.Xpiro.2
TACHYONTrojan/W32.Zomex.Zen
Cylanceunsafe
RisingVirus.Zombie!1.AB2A (CLASSIC)
IkarusVirus.Win32.Agent
FortinetW32/Agent.NBJ!tr
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS

How to remove Ransom.Xpiro.2?

Ransom.Xpiro.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment