Malware

Should I remove “W32.Xpaj.A”?

Malware Removal

The W32.Xpaj.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32.Xpaj.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine W32.Xpaj.A?


File Info:

name: F8B73B28217A57070042.mlw
path: /opt/CAPEv2/storage/binaries/1925cf9900b9421efc9226bfdf549984be8c2304451d46df10914cbe24c421fa
crc32: F8EC0C2F
md5: f8b73b28217a57070042e96fa2a60d77
sha1: d35dc9b4064afe11c8505216be2c8d527c0950d7
sha256: 1925cf9900b9421efc9226bfdf549984be8c2304451d46df10914cbe24c421fa
sha512: b344f3799a9a9c71460830b747faf2d76080aa0f680ed692aa7c2cd71aa1755abae4cd37724b858f999ac9fa3a101c9076b7a49a7c38a72c6f469c2751ab667c
ssdeep: 12288:H7Pt1oVcjtR2OnT0oRjNxTVIdNL7+B7YLA8L1dRB8Gjxe9X:bnpwuYoRjNxTKL7+B7YL/LNC8xwX
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T114255B63B582A1B0E985867541B7633F933C8E119B11CAE7D210B81AFD773D18B79ACC
sha3_384: 1f94373b61de26b9c2bc1ab391b980f19958282b7400c10c0e5471662cdf925de8cb0cd6f839613f0d925d965a322de0
ep_bytes: 53b8010000008b5c240c565785db5575
timestamp: 1998-06-22 21:39:12

Version Info:

CompanyName: Intel Corporation
FileDescription: Intel Indeo® Video 4.5
FileVersion: 4.51.16.03
InternalName: ir41_32.ax
LegalCopyright: Copyright© Intel Corporation 1994-1998
LegalTrademarks: Indeo® is a registered trademark of Intel Corporation
OriginalFilename: ir41_32.ax
ProductName: Intel Indeo® Video 4.5
ProductVersion: 4.51.16.03
Translation: 0x0409 0x04e4

W32.Xpaj.A also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Xpaj.n!c
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Xpaj-2
FireEyeGeneric.mg.f8b73b28217a5707
CAT-QuickHealW32.Xpaj.A
SkyhighBehavesLike.Win32.Worm.dh
McAfeeArtemis!F8B73B28217A
MalwarebytesXpaj.Virus.FileInfector.DDS
K7AntiVirusVirus ( 005ab3521 )
AlibabaVirus:Win32/Goblin.30f3bb1c
K7GWVirus ( 005ab3521 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Virus.Xpaj.gen
SymantecW32.Xpaj.C
ESET-NOD32Win32/Goblin.A.Gen
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Goblin.gen
BitDefenderWin32.XPaj.B
NANO-AntivirusVirus.Win32.Goblin.bcufsv
MicroWorld-eScanWin32.XPaj.B
AvastWin32:Goblin
TencentVirus.Win32.Goblin.ka
EmsisoftWin32.XPaj.B (B)
F-SecureMalware.W32/Xpaj.A
DrWebWin32.Goblin
VIPREWin32.XPaj.B
TrendMicroPE_XPAJ.A-1
SophosMal/Xpaj-A
IkarusVirus.Win32.Xpaj
VaristW32/Xpaj.C.gen!Eldorado
AviraW32/Xpaj.A
Antiy-AVLVirus/Win32.Goblin.a
MicrosoftVirus:Win32/Xpaj.gen!A
ArcabitWin32.XPaj.B
ZoneAlarmVirus.Win32.Goblin.gen
GDataWin32.XPaj.B
GoogleDetected
AhnLab-V3Win32/Xpaj
ALYacWin32.XPaj.B
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Chgt.AC
TrendMicro-HouseCallPE_XPAJ.A-1
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Goblin.A
BitDefenderThetaAI:FileInfector.EA694EEA0C
AVGWin32:Goblin
DeepInstinctMALICIOUS

How to remove W32.Xpaj.A?

W32.Xpaj.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment