Ransom Trojan

Trojan-Ransom.Win32.Xpan.a information

Malware Removal

The Trojan-Ransom.Win32.Xpan.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Xpan.a virus can do?

  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Xpan.a?


File Info:

crc32: AAD2E2A6
md5: 1776f6b254eaf604201c56c8f2fbedc9
name: 1776F6B254EAF604201C56C8F2FBEDC9.mlw
sha1: 9e5ee890c3302fc0daa300b5506d6766caff4654
sha256: 175351fcd9f6a0a6658fd1241004c9760372b3a6771aa635880668e20e78c627
sha512: 94a77080c497a1987faca6e6fcdf8492abe4598503bb79892138722f4097fc325db46d66cc179f8dd760128bf21d9a68c95990b3ccc7945074989b17455d2af7
ssdeep: 24576:Bm4hcuoNvTg5Xk1ABXeSdeZrKuhfD8q6xMpDCiiYUMa:BmPLhf16xMpDCiiYU
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Xpan.a also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Xpan.4!c
DrWebTrojan.Encoder.6333
ALYacTrojan.Patched.SAP.Gen
CylanceUnsafe
ZillyaTrojan.Xpan.Win32.4
SangforRansom.Win32.Xpan.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/XRatLocker.d738e774
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.254eaf
SymantecRansom.Xpan
ESET-NOD32Win32/Filecoder.XRatLocker.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Xpan.a
BitDefenderTrojan.Patched.SAP.Gen
NANO-AntivirusTrojan.Win32.Xpan.egpctb
MicroWorld-eScanTrojan.Patched.SAP.Gen
TencentTrojan-Ransom.Win32.XratLocker.a
Ad-AwareTrojan.Patched.SAP.Gen
SophosMal/Generic-S
ComodoMalware@#256gevun98e9l
BitDefenderThetaGen:NN.ZexaF.34170.GLW@a85SaDi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericR-PFQ!1776F6B254EA
FireEyeGeneric.mg.1776f6b254eaf604
EmsisoftTrojan.Patched.SAP.Gen (B)
JiangminTrojan.Xpan.a
Antiy-AVLTrojan/Generic.ASMalwS.1BE2D7E
MicrosoftRansom:Win32/Xpan.A
GDataTrojan.Patched.SAP.Gen
McAfeeGenericR-PFQ!1776F6B254EA
MAXmalware (ai score=100)
VBA32Hoax.Xpan
PandaTrj/Ransom.CD
YandexTrojan.GenAsa!5Mpmstx0OeQ
IkarusTrojan-Ransom.Xratlocker
FortinetW32/XRatLocker.A!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Xpan.a?

Trojan-Ransom.Win32.Xpan.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment