Ransom

Ransom:Win32/Xpan.A information

Malware Removal

The Ransom:Win32/Xpan.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Xpan.A virus can do?

  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Xpan.A?


File Info:

crc32: 0424B900
md5: 096b0a2b95e483e22e43196766af50ae
name: 096B0A2B95E483E22E43196766AF50AE.mlw
sha1: 31af17ce65878cc1f7bdff5e15ace85051a8296e
sha256: a2f293ae5133ef7b7432537f944e768bfce23e51b16031ac17f9d72376af3f30
sha512: 82237088a23854cc581858856c0b379f6d8c20ebc21757dd60e82d6a3b530edffd14481dff0d1811c5a5f82e8eba6740ef7df0ba358809159b86cdc840518bc3
ssdeep: 6144:5xqqPbZsXzqYjLSiI3FdoNc6BbbcF7m8Lb3Q8loI79RIhARB1n9qPcLIsgnmR0:5xUXzqOWrFCNdkZNf8K19q2qm
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/Xpan.A also known as:

BkavW32.AIDetect.malware2
FireEyeGen:Variant.Ransom.XRatLocker.9
McAfeeArtemis!096B0A2B95E4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Xpan.4!c
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3ef1 )
BitDefenderGen:Variant.Ransom.XRatLocker.9
K7GWTrojan ( 0055e3ef1 )
SymantecRansom.Xpan
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 90)
KasperskyTrojan-Ransom.Win32.Xpan.a
AlibabaRansom:Win32/XRatLocker.c05da479
NANO-AntivirusTrojan.Win32.Xpan.egpctb
MicroWorld-eScanGen:Variant.Ransom.XRatLocker.9
RisingRansom.Xpan!8.DD6E (CLOUD)
Ad-AwareGen:Variant.Ransom.XRatLocker.9
EmsisoftGen:Variant.Ransom.XRatLocker.9 (B)
F-SecureHeuristic.HEUR/AGEN.1101738
DrWebTrojan.Encoder.6333
ZillyaTrojan.Xpan.Win32.1
TrendMicroHT_CRYPXPAN_GB010014.UVPM
McAfee-GW-EditionRansomware-FUK!95957AFBA98B
SophosMal/Generic-S
IkarusTrojan-Ransom.Xratlocker
JiangminTrojan.Xpan.a
MaxSecureTrojan.Malware.9951292.susgen
AviraHEUR/AGEN.1101738
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Xpan
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Xpan.A
ArcabitTrojan.Ransom.XRatLocker.9
ZoneAlarmTrojan-Ransom.Win32.Xpan.a
GDataGen:Variant.Ransom.XRatLocker.9
AhnLab-V3Trojan/Win32.Xpan.C1604517
BitDefenderThetaGen:NN.ZexaF.34590.vmGfamJQvqc
ALYacGen:Variant.Ransom.XRatLocker.9
VBA32Hoax.Xpan
MalwarebytesMalware.AI.3797023223
PandaTrj/Ransom.CD
ESET-NOD32a variant of Win32/Filecoder.XRatLocker.A
TrendMicro-HouseCallHT_CRYPXPAN_GB010014.UVPM
TencentTrojan-Ransom.Win32.XratLocker.a
YandexTrojan.GenAsa!HwW+vuoQkrM
FortinetW32/XRatLocker.A!tr
AVGFileRepMalware
Cybereasonmalicious.b95e48
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASOkA

How to remove Ransom:Win32/Xpan.A?

Ransom:Win32/Xpan.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment