Trojan

Trojan.Xanfpezes removal tips

Malware Removal

The Trojan.Xanfpezes is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Xanfpezes virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan.Xanfpezes?


File Info:

name: 3F84502DDD0632F626CE.mlw
path: /opt/CAPEv2/storage/binaries/434ce6e9f87b670a007ba39b4e67fe4331da8a558313338bd5c11bcb8599295e
crc32: 8579E2C0
md5: 3f84502ddd0632f626ce814754f069c1
sha1: 00174b76b31eb152c9ec6251812c3405db23301f
sha256: 434ce6e9f87b670a007ba39b4e67fe4331da8a558313338bd5c11bcb8599295e
sha512: 8fc6d0a00c2831c7a159d409855c425b5c1fd5c1e23d403d760ddef59d24858755e5856e24bc10d54f1f98fd9b3811a1afbe3819c3b481691e335a669a474af7
ssdeep: 98304:K7zttrRvazttrRevazKRvazttreRvazttBeRv+trBzttreR5:K7RtdvaRtdevaSvaRtmvaRtov+t9Rtm5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191969F62F292D433E5A22B349E6B82E467397D006E74964B37F42F0D3F75A4239253D2
sha3_384: a8596c8a17ed33e5749a5034ce90a991d2334d4da9ad8b926ae5bc17957af3a04b3db1e2a76ccc589a016eeeff68d865
ep_bytes: 558bec83c4e45333c08945e48945ec89
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Xanfpezes also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38148986
FireEyeGeneric.mg.3f84502ddd0632f6
McAfeeGenericR-AVZ!3F84502DDD06
CylanceUnsafe
ZillyaTrojan.Xanfpezes.Win32.7
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001496011 )
K7GWTrojan ( 001496011 )
Cybereasonmalicious.6b31eb
BitDefenderThetaGen:NN.ZelphiF.34084.@RZ@aOXtgPbb
CyrenW32/DelfInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Xanfpezes.A
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.38148986
NANO-AntivirusTrojan.Win32.Xanfpezes.edtzt
AvastWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKD.38148986
EmsisoftTrojan.GenericKD.38148986 (B)
DrWebTrojan.MulDrop5.37095
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.PUPXCD.rh
SentinelOneStatic AI – Malicious PE
SophosTroj/Ghetifuh-A
APEXMalicious
GDataWin32.Trojan.PSE.1J352IY
MaxSecureTrojan.Malware.2588.susgen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.185BCB3
ArcabitTrojan.Generic.D2461B7A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R345760
VBA32BScope.Trojan.AntiAV
ALYacTrojan.GenericKD.38148986
MAXmalware (ai score=81)
MalwarebytesTrojan.Xanfpezes
RisingTrojan.Generic@ML.95 (RDML:dasE0UcxOeeD5D3Im310Dw)
IkarusTrojan.Win32.Xanfpezes
eGambitUnsafe.AI_Score_99%
FortinetW32/Xanfpezes.ACMT!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Trojan.Xanfpezes?

Trojan.Xanfpezes removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment