Virus

Virus:Win32/Xpaj!C removal

Malware Removal

The Virus:Win32/Xpaj!C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Xpaj!C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Virus:Win32/Xpaj!C?


File Info:

name: FB3DA8BD986D5D1C455F.mlw
path: /opt/CAPEv2/storage/binaries/fa74416efc8317b2e54b9d47012083faa4d45719a203690602a5ba7d8630d73e
crc32: 4B8C45D9
md5: fb3da8bd986d5d1c455f65b0c42ef62d
sha1: 690f38b5ba93fbe593723cf2b3dcac452c5b8a21
sha256: fa74416efc8317b2e54b9d47012083faa4d45719a203690602a5ba7d8630d73e
sha512: cdb99c988d1c6586e861aed57ed699d20a0c296aeccfb0345e9a8cf0a00335eb476ea37c0bfec7725c7b473fa2128740d6afc82fc90f655cf394bb60ecf6155b
ssdeep: 6144:GNYFfL8CSJwfMMdbt3DMwfS18jCMd+1X8a1lfrZ1h4zEXjr:dLGJcMMdVv4M2sa15rZ1GITr
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T13674AC90B200C0B1D0A6B27549DB22B5B5BA5DD3CF6185C33EEC6E5A7E35DE22D35382
sha3_384: 8c32adba9f61a36a76452d8dfaf13c9ef65cf6038b65a5c10dc22fc01cd82fc05fe330dbc54fa76301f4d87862592180
ep_bytes: 8bff558bec837d0c017505e8f3080000
timestamp: 2070-04-17 23:45:57

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Media Player Visualization
FileVersion: 12.0.17134.1 (WinBuild.160101.0800)
InternalName: mpvis.dll
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: mpvis.dll
ProductName: Microsoft® Windows® Operating System
ProductVersion: 12.0.17134.1
Translation: 0x0409 0x04b0

Virus:Win32/Xpaj!C also known as:

BkavW32.XpajA.PE
LionicVirus.Win32.Xpaj.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.XPaj.C
ClamAVBC.Win.Trojan.Xpaj-7
FireEyeGeneric.mg.fb3da8bd986d5d1c
CAT-QuickHealW32.Xpaj.C
SkyhighBehavesLike.Win32.Xpaj.fc
McAfeeW32/Xpaj.b
Cylanceunsafe
SangforVirus.Win32.Xpaj.Vjaj
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Goblin.aa305be0
K7GWVirus ( 700000051 )
K7AntiVirusVirus ( 700000051 )
BaiduWin32.Virus.Xpaj.a
SymantecW32.Xpaj.B
ESET-NOD32Win32/Goblin.D.Gen
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Xpaj.gen
BitDefenderWin32.XPaj.C
NANO-AntivirusVirus.Win32.Xpaj.blcbg
AvastWin32:Xpaj
TencentVirus.Win32.Xpaj.tt
SophosMal/Xpaj-B
F-SecureMalware.W32/Xpaj.C
DrWebWin32.Xpaj.1
VIPREWin32.XPaj.C
TrendMicroPE_XPAJ.A
EmsisoftWin32.XPaj.C (B)
GDataWin32.XPaj.C
JiangminWin32/Xpaj.Gen
GoogleDetected
AviraW32/Xpaj.C
Antiy-AVLVirus/Win32.Xpaj.gen
ArcabitWin32.XPaj.C
ZoneAlarmVirus.Win32.Xpaj.gen
MicrosoftVirus:Win32/Xpaj.gen!C
VaristW32/Xpaj.A
VBA32Virus.Xpaj.gen
ALYacWin32.XPaj.C
MAXmalware (ai score=88)
MalwarebytesMalware.AI.2955076572
PandaW32/Xpaj.b
TrendMicro-HouseCallPE_XPAJ.A
IkarusVirus.Win32.Xpaj
MaxSecureVirus.Xpaj.Gen
FortinetW32/Xpaj.fam
BitDefenderThetaAI:FileInfector.9D6E7E7C0C
AVGWin32:Xpaj
DeepInstinctMALICIOUS

How to remove Virus:Win32/Xpaj!C?

Virus:Win32/Xpaj!C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment