Rootkit

How to remove “Rootkit.Win32.Xanfpezes.ccq”?

Malware Removal

The Rootkit.Win32.Xanfpezes.ccq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.Win32.Xanfpezes.ccq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Rootkit.Win32.Xanfpezes.ccq?


File Info:

name: 98CDA079AE6E9365431C.mlw
path: /opt/CAPEv2/storage/binaries/7d0fe7791f8c062ccf0cbafe98d425b78c7d53a71076bc296fd53540ac5c902d
crc32: DAB650F8
md5: 98cda079ae6e9365431c11e70a7832d5
sha1: ee80e762ef204914f704ba668546079e8abe0dd5
sha256: 7d0fe7791f8c062ccf0cbafe98d425b78c7d53a71076bc296fd53540ac5c902d
sha512: 1636ada591b5b28f862887b14a5f0e25a6bf42a78a9415d238c3947b649fd34d8c460b261632ec3751f6b09f0c239773273d28045f1458354a51f92fff08413a
ssdeep: 98304:b0tZ5CqZNWLemiaAwD7NWLemiaA5miaAwD7NWLeLF:b/qI5P85PZP8SF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D416AE65F281E433E0A62F304E27C2E46739B9946E75955F33F42F4E3A75A837621382
sha3_384: 0c742a329944d3671e5b23c599cd9461bbf0d0a5cbd68aa9c0848186df150ac3fd99f9feba522d36b4fa1eabd21a59d1
ep_bytes: 558bec83c4e053565733c08945e08945
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Rootkit.Win32.Xanfpezes.ccq also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.36923
FireEyeGeneric.mg.98cda079ae6e9365
CAT-QuickHealTrojan.Rootkitdrv
McAfeeXanfpezes.a
MalwarebytesMalware.AI.3262377124
ZillyaRootkit.Xanfpezes.Win32.24
K7AntiVirusTrojan ( 001496011 )
Cybereasonmalicious.9ae6e9
CyrenW32/DelfInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Xanfpezes.A
APEXMalicious
KasperskyRootkit.Win32.Xanfpezes.ccq
BitDefenderGen:Variant.Fugrafa.36923
NANO-AntivirusTrojan.Win32.MLW.ejqaa
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Generic@ML.94 (RDML:wBQT46ZbUmatL3i84CqqLQ)
Ad-AwareGen:Variant.Fugrafa.36923
SophosTroj/Ghetifuh-A
DrWebTrojan.Click1.28484
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_UNDEF.RX
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
EmsisoftGen:Variant.Fugrafa.36923 (B)
SentinelOneStatic AI – Malicious PE
JiangminHeur:Rootkit/Agent
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.55ED8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Fugrafa.36923
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Xanfpezes.C4075368
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34294.@RZ@aub0uOhb
ALYacGen:Variant.Fugrafa.36923
MAXmalware (ai score=84)
VBA32Rootkit.Xanfpezes
CylanceUnsafe
TrendMicro-HouseCallTROJ_UNDEF.RX
TencentMalware.Win32.Gencirc.11d970cf
YandexTrojan.GenAsa!vO1+7JyoNgg
IkarusTrojan.Win32.Xanfpezes
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Xanfpezes.A!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Rootkit.Win32.Xanfpezes.ccq?

Rootkit.Win32.Xanfpezes.ccq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment