Malware

How to remove “W32/Xolxo-G”?

Malware Removal

The W32/Xolxo-G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Xolxo-G virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine W32/Xolxo-G?


File Info:

name: 7D67A66CDF6043736641.mlw
path: /opt/CAPEv2/storage/binaries/21b117cdaf06edeab98064042dd32597d9ce20b13942fe07e9b3c893e419c74a
crc32: 95F754A7
md5: 7d67a66cdf6043736641721fc594adac
sha1: b054b1c210fbe634c4b47caf4d38bb076f222aaa
sha256: 21b117cdaf06edeab98064042dd32597d9ce20b13942fe07e9b3c893e419c74a
sha512: 7f5657094df0dd5147ae92c606f6f2dc82dd671a76c872177b953b34d74a0eaab85d0b55a6438f908380dd450c92322fef32e0fca783d0c0553afd0b02810010
ssdeep: 12288:rJTfDYmIjE7+1gL5pRTcAkS/3hzN8qE43fm78Vh:rJjh7H5jcAkSYqyEh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB054A15F6748671D073C0B9C5D2A69AEE3230465B308ACB138AD7782F677E6C93A731
sha3_384: 3255b0afb1921a1b901f20691e12e6f5c5a412307a7ca1e1926a39b3654db984c6d01bcdc0d5157d77f3b4d0b30e0920
ep_bytes: 558bec83c4f0b838464000e874e2ffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

W32/Xolxo-G also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EICV
CAT-QuickHealWorm.DelfPMF.S30896276
SkyhighBehavesLike.Win32.Generic.bm
McAfeeW32/HLLP.11042.gen
MalwarebytesGeneric.Trojan.Delf.DDS
VIPRETrojan.Agent.EICV
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053c5661 )
K7GWTrojan ( 0053c5661 )
Cybereasonmalicious.210fbe
BaiduWin32.Virus.Lamer.f
SymantecW32.SillyP2P
ESET-NOD32Win32/Delf.NAY
APEXMalicious
ClamAVWin.Virus.Wapomi-9623880-0
KasperskyP2P-Worm.Win32.Delf.aj
BitDefenderTrojan.Agent.EICV
NANO-AntivirusTrojan.Win32.Delf.oxkq
AvastWin32:Delf-SVI [Trj]
RisingWorm.P2p.Win32.Delf.bn (CLASSIC)
EmsisoftTrojan.Agent.EICV (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Kazaa.924
ZillyaWorm.Delf.Win32.3450
TrendMicroTROJ_AGENT_005911.TOMB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7d67a66cdf604373
SophosW32/Xolxo-G
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
GDataWin32.Trojan.PSE.10YRRCT
JiangminWorm/Delf.vm
WebrootW32.Worm.Gen
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Delf.QB.gen!Eldorado
Antiy-AVLVirus/Win32.BagarBubba.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Pincav.AV@2rw0ny
ArcabitTrojan.Agent.EICV
ZoneAlarmP2P-Worm.Win32.Delf.aj
MicrosoftWorm:Win32/Xolxo.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Delf.R119214
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.36744.XmZ@auciUnn
ALYacTrojan.Agent.EICV
VBA32Worm.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_005911.TOMB
TencentVirus.Win32.Lamer.fh
IkarusTrojan.Agent
MaxSecureVirus.W32.Lamer.FG
FortinetW32/Aple.A
AVGWin32:Delf-SVI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove W32/Xolxo-G?

W32/Xolxo-G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment