Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

About “Virus.Goblin.2521” infection

Published Apr 22, 2024 Virus category 3 min read
Report context

What to verify before removal

Use this report for a controlled check of About “Virus.Goblin.2521” infection when the affected machine shows suspicious processes, dropped files, or payload delivery behavior. The goal is to verify the exact file and persistence path before quarantine.

Start by comparing the local file name with 62A60AF9DEFA54C15401.mlw, then review the behavior notes for persistence entries, dropped files, unusual processes, and browser or network changes. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
62A60AF9DEFA54C15401.mlw
  • Compare the suspicious file name with 62A60AF9DEFA54C15401.mlw.
  • Confirm the detection name matches About “Virus.Goblin.2521” infection before removing related files.
  • Review the report for persistence entries, dropped files, unusual processes, and browser or network changes so the cleanup is based on observed behavior, not only the label.
  • Run a full scan, quarantine confirmed detections, and restart before signing back in to sensitive accounts.

The Virus.Goblin.2521 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Virus.Goblin.2521 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus.Goblin.2521?


File Info:

name: 62A60AF9DEFA54C15401.mlw
path: /opt/CAPEv2/storage/binaries/53adc4d70ecf45f044c6f35208dfb7937435968b94c0ec9a70b2fec8c5273f2c
crc32: 42948477
md5: 62a60af9defa54c15401c3e9fe5a49ee
sha1: 2a9034c3a333c200c8e9ef5e178f410e9bb467c3
sha256: 53adc4d70ecf45f044c6f35208dfb7937435968b94c0ec9a70b2fec8c5273f2c
sha512: 5cb357df2565eb89a65349e0da144a85e286cd056337c5c7e16c29f38e2537cbc3c989ffc326d1d2182db0696b9e94381469bde1cbc6f7ef3b497c70fdbb5b57
ssdeep: 3072:rOm3i+pRbScFFZvjtYCmoXSihpe5cI9XBJ1IcmFj:5jlbaihpel1A
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1C5E39E423EC35475D2C906B177EB9B77EE3168329E2CC3D7EB909E21BA704C1626B614
sha3_384: 0ac3b25ad6b4beed1d476a3fce4e446b3d73fc47f97a83cfc459106125f76539348ce21c439ae7bfa5c4e3b66bd6067b
ep_bytes: e8c1bd0000837c24080175108b442404
timestamp: 2017-09-07 16:50:40

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Jet Database Engine International DLL
FileVersion: 4.00.9801.1
InternalName: MSJINT40.DLL
LegalCopyright: Copyright © Microsoft Corp. 1991-1999 All rights reserved.
OriginalFilename: MSJINT40.DLL
ProductName: Microsoft (R) Jet
ProductVersion: 4.00.9801.1
Translation: 0x0409 0x04b0

Virus.Goblin.2521 also known as:

Bkav W32.AIDetectMalware
ClamAV Win.Trojan.Xpaj-2
FireEye Generic.mg.62a60af9defa54c1
CAT-QuickHeal W32.Xpaj.A
Skyhigh BehavesLike.Win32.Generic.cc
ALYac Win32.XPaj.B
Cylance unsafe
Sangfor Virus.Win32.Xpaj.V83r
Alibaba Virus:Win32/Goblin.f078ca3a
K7GW Virus ( 005ab3521 )
K7AntiVirus Virus ( 005ab3521 )
Arcabit Win32.XPaj.B
Baidu Win32.Virus.Xpaj.gen
Symantec W32.Xpaj.C
ESET-NOD32 Win32/Goblin.A.Gen
APEX Malicious
Cynet Malicious (score: 100)
Kaspersky Virus.Win32.Goblin.gen
BitDefender Win32.XPaj.B
NANO-Antivirus Virus.Win32.Goblin.bcufsv
MicroWorld-eScan Win32.XPaj.B
Avast Win32:Goblin
Tencent Virus.Win32.Goblin.ka
Emsisoft Win32.XPaj.B (B)
F-Secure Malware.W32/Xpaj.A
DrWeb Win32.Goblin
VIPRE Win32.XPaj.B
TrendMicro PE_XPAJ.A-1
Sophos Mal/Xpaj-A
SentinelOne Static AI – Suspicious PE
Varist W32/Goblin.A.gen!Eldorado
Avira W32/Xpaj.A
Antiy-AVL Virus/Win32.Goblin.a
Kingsoft Win32.Infected.AutoInfector.a
Microsoft Virus:Win32/Xpaj.gen!A
ZoneAlarm Virus.Win32.Goblin.gen
GData Win32.XPaj.B
Google Detected
AhnLab-V3 Win32/Xpaj
MAX malware (ai score=100)
VBA32 Virus.Goblin.2521
Malwarebytes Xpaj.Virus.FileInfector.DDS
Panda Generic Suspicious
TrendMicro-HouseCall PE_XPAJ.A-1
Ikarus Virus.Win32.Xpaj
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Goblin.A
BitDefenderTheta AI:FileInfector.EA694EEA0C
AVG Win32:Goblin
DeepInstinct MALICIOUS

How to remove Virus.Goblin.2521?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.