Virus

Should I remove “Virus:Win32/Xorer.O”?

Malware Removal

The Virus:Win32/Xorer.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Xorer.O virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Xorer.O?


File Info:

name: B93FA26071855E227A47.mlw
path: /opt/CAPEv2/storage/binaries/238ae53359d0b6ada33e87545c7e20e2deaecb30759a4e3e1f0e69697a9ea8c4
crc32: B317AFC2
md5: b93fa26071855e227a4752322aae44a0
sha1: 4c5fd319018cf096e77fc43729fbfd47d89db074
sha256: 238ae53359d0b6ada33e87545c7e20e2deaecb30759a4e3e1f0e69697a9ea8c4
sha512: 53d650c7ab04bde4a289c8e3203560d27759a8e9a4aef660ff2fb44c8b708c149a751db3cb8cd3bd9999aeb1c678db02306edb119f079977a3c66643bbda0930
ssdeep: 3072:fEuI6jiO7wYxnyl6ckCJe6ElZdoBYxQq/pnQZrrBSD+rgePiZuVm22zl+F4TZFAK:fsw7MXklLPWrYDyBK4k+STZFXX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167340249B702DE06EA109136CD19DAFDAB62FDD8CE56400736D9FFAF78BE6109844702
sha3_384: ca65fcd453c2e8c5546fdcdd16a3ca9afdac5ebe117e4cb946bd60bce47752ff8e8c342c74b20d732cf9369083fab855
ep_bytes: 60be005041008dbe00c0feff5783cdff
timestamp: 2008-02-27 14:46:19

Version Info:

0: [No Data]

Virus:Win32/Xorer.O also known as:

BkavW32.DashferDP.PE
LionicVirus.Win32.Xorer.lzKz
Elasticmalicious (moderate confidence)
MicroWorld-eScanGeneric.Xorer.586CE9F3
ClamAVWin.Worm.Xorer-106
FireEyeGeneric.mg.b93fa26071855e22
CAT-QuickHealW32.Switch.A
SkyhighBehavesLike.Win32.PWSQQPass.dh
McAfeeArtemis!B93FA2607185
Cylanceunsafe
ZillyaVirus.Xorer.Win32.15
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 001355dd1 )
AlibabaVirus:Win32/Xorer.430f3319
K7GWVirus ( 001355dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36680.pmJfa49a5Pkb
SymantecW32.Pagipef.B
ESET-NOD32a variant of Win32/Xorer
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Xorer.ej
BitDefenderGeneric.Xorer.586CE9F3
NANO-AntivirusVirus.Win32.Xorer.giyk
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.DiskGen.m
EmsisoftGeneric.Xorer.586CE9F3 (B)
BaiduWin32.Virus.Xorer.a
F-SecureTrojan.TR/Drop.Xorer.C
DrWebWin32.HLLP.Rox.9
VIPREGeneric.Xorer.586CE9F3
TrendMicroPE_PAGIPEF.BP
SophosW32/Xorer-D
IkarusVirus.Win32.Xorer
GDataGeneric.Xorer.586CE9F3
JiangminWin32/Kdcyy.bs
GoogleDetected
AviraTR/Drop.Xorer.C
KingsoftWin32.Infected.AutoInfector.a
XcitiumTrojWare.Win32.TrojanDropper.Xorer.~B@fnz2
ArcabitGeneric.Xorer.586CE9F3
ViRobotWin32.Xorer.K
ZoneAlarmVirus.Win32.Xorer.ej
MicrosoftVirus:Win32/Xorer.O
VaristW32/Xorer.EXUI-6695
AhnLab-V3Win32/Diskgen.Gen
VBA32Virus.Win32.Xorer.gn
ALYacGeneric.Xorer.586CE9F3
MAXmalware (ai score=100)
MalwarebytesXorer.Virus.FileInfector.DDS
PandaTrj/Downloader.SVM
TrendMicro-HouseCallPE_PAGIPEF.BP
RisingWorm.Win32.DiskGen.gfc (CLOUD)
YandexTrojan.GenAsa!mykyivRSZEM
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Xorer.EJ
FortinetW32/Xorer.DR
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.9018cf
DeepInstinctMALICIOUS

How to remove Virus:Win32/Xorer.O?

Virus:Win32/Xorer.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment