Virus

About “Virus:Win32/Xorer.J” infection

Malware Removal

The Virus:Win32/Xorer.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Xorer.J virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to identify installed AV products by registry key
  • Creates a copy of itself
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Virus:Win32/Xorer.J?


File Info:

name: E2CC82380C187F9AF382.mlw
path: /opt/CAPEv2/storage/binaries/37b7b7d0db2d4f6dc129763ab69e513eb23bba271e620bdc3f5d990a8f5c012b
crc32: 7C670C84
md5: e2cc82380c187f9af382b94652b07969
sha1: 72832a430148519f5f73a1325f2b88f956a5a195
sha256: 37b7b7d0db2d4f6dc129763ab69e513eb23bba271e620bdc3f5d990a8f5c012b
sha512: 6eac687cb0d78e273f683cd052ee366f38a0978825bab3933c4044b22dedc1c5111bb3c42e427f365d24e1c1203afbaefbdcab1325ba5ae413ef1a35e1086b07
ssdeep: 3072:GJiVIzsPZFzcyofgzCdrS8X+MI8xQO1r+UYGrkIcX:G8fsyofgzKw8xQOc7ukz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16234D017BC558947E17A0971660E27EDC3335D311BB46A932B60BFBD1A3AC92CC2493E
sha3_384: 3bfb9a00fc0300eb0e8a4e12f1cfc7a99c7dcc79ea944211c6e3cdd2f4f911babb86c9d9f57cd9029196f664142040f7
ep_bytes: 558bec6aff6840974000684a80400064
timestamp: 2008-03-15 09:35:50

Version Info:

0: [No Data]

Virus:Win32/Xorer.J also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.Xorer.lzKz
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Xorer.T
FireEyeGeneric.mg.e2cc82380c187f9a
McAfeeW32/Xorer.g
CylanceUnsafe
VIPRETrojan.Xorer.T
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderTrojan.Xorer.T
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.80c187
BitDefenderThetaGen:NN.ZexaF.34646.pmW@a4pGgSeb
CyrenW32/Busky.B.gen!Eldorado
SymantecW32.Pagipef.I!inf
ESET-NOD32Win32/Xorer
BaiduWin32.Virus.Xorer.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DIH22
Paloaltogeneric.ml
ClamAVWin.Trojan.Xorer-12
KasperskyVirus.Win32.Xorer.ew
AlibabaVirus:Win32/Xorer.1807e165
NANO-AntivirusVirus.Win32.Xorer.giyk
RisingWorm.Win32.DiskGen.gfp (CLASSIC)
Ad-AwareTrojan.Xorer.T
ComodoWin32.Xorer@ac4g
DrWebWin32.HLLP.Rox.21
TrendMicroTROJ_GEN.R002C0DIH22
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dm
Trapminemalicious.high.ml.score
SophosMal/Xorer-A
APEXMalicious
JiangminWin32/Kdcyy.ci
AviraTR/Xorer.174009
MAXmalware (ai score=82)
MicrosoftVirus:Win32/Xorer.J
GDataTrojan.Xorer.T
GoogleDetected
VBA32Virus.Win32.Xorer.gn
ALYacTrojan.Xorer.T
IkarusTrojan-Dropper.Xorer
PandaW32/Pagepif.G.worm
TencentVirus.Win32.DiskGen.p
YandexTrojan.GenAsa!g4zcd40aHaw
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Xorer
FortinetW32/Xorer.DR
AVGWin32:Xorer-J
AvastWin32:Xorer-J
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Xorer.J?

Virus:Win32/Xorer.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment