Virus

Virus.Xorer (file analysis)

Malware Removal

The Virus.Xorer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Xorer virus can do?

  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Virus.Xorer?


File Info:

crc32: 0D54749D
md5: 2c852c113e3d71e453d0a5d2e6f0e080
name: 2C852C113E3D71E453D0A5D2E6F0E080.mlw
sha1: 89df75c21e8af961990b2aefe2b2ffa4817de5bb
sha256: 8d6ac3ab639c407d3c9e968f300e8d418feb20715225cbbed9b0452e70887c0a
sha512: 56ed5c2e7b4aab8455e0d38bf597f38e72131ac4c66ac18dd2e16024d924bfa1ea60ced06d5f04d96d73a2ae4eec1a5ce7ef876a2fdf2fd66e2ca2980ee8ca7b
ssdeep: 768:m4gu4yiCPNPJx8YIOnYzr3g7QRYs8NdisKl4qR:554Q19FUR8NdisKldR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Virus.Xorer also known as:

BkavW32.Startup10KT.Trojan
K7AntiVirusTrojan ( 0040f9601 )
TotalDefenseWin32/Pagipef!generic
MicroWorld-eScanTrojan.Agent.DCFC
CMCEmail-Worm.Win32.Runouce!O
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Agent.DCFC
CylanceUnsafe
ZillyaWorm.Small.Win32.1243
CrowdStrikemalicious_confidence_100% (D)
K7GWTrojan ( 0040f9601 )
Cybereasonmalicious.13e3d7
TrendMicroPE_PAGIPEF.BT
BaiduWin32.Virus.Xorer.k
NANO-AntivirusVirus.Win32.Xorer.zotjm
CyrenW32/Trojan.ELLV-0032
SymantecW32.Chir.B@mm
ESET-NOD32Win32/Small.NAV
TheHackerTrojan/Small.nav
AvastWin32:Agent-BARL [Trj]
ClamAVWin.Worm.Brontok-88
GDataTrojan.Agent.DCFC
KasperskyVirus.Win32.Xorer.dr
BitDefenderTrojan.Agent.DCFC
ViRobotWin32.Pagipef.A
TencentVirus.Win32.ChineseHackerRes.a
Ad-AwareTrojan.Agent.DCFC
SophosTroj/Agent-KBA
F-SecureTrojan.Agent.DCFC
DrWebTrojan.Click.1772
VIPREWin32.Chir.b!dam (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Autorun.nt
EmsisoftTrojan.Agent.DCFC (B)
SentinelOnestatic engine – malicious
F-ProtW32/Trojan.NLE
Endgamemalicious (high confidence)
WebrootW32.Trojan.Gen
AviraW32/Chir.B
Antiy-AVLVirus/Win32.Xorer.dr
KingsoftWin32.Vcing.ae.760328
MicrosoftVirus:Win32/Chir.B@mm
JiangminWorm/AutoRun.eqe
ArcabitTrojan.Agent.DCFC
ZoneAlarmVirus.Win32.Xorer.dr
McAfeeW32/HLLP.Sassy.a
MAXmalware (ai score=87)
VBA32Virus.Win32.Xorer.gs
MalwarebytesVirus.Xorer
PandaW32/Chir.P.worm
TrendMicro-HouseCallPE_PAGIPEF.BT
RisingVirus.Chir!1.A11C (CLASSIC)
YandexTrojan.Agent!TTTzxXMcoG8
IkarusTrojan.Win32.Agent
FortinetW32/Xorer.DR
AVGWin32:Agent-BARL [Trj]
Qihoo-360Malware.Radar03.Gen

How to remove Virus.Xorer?

Virus.Xorer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment