Malware

How to remove “Win32/Xanfpezes.E”?

Malware Removal

The Win32/Xanfpezes.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Xanfpezes.E virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Xanfpezes.E?


File Info:

name: 10269F6657D20A408BFF.mlw
path: /opt/CAPEv2/storage/binaries/986290d98191d294fa6824f910276426731929525bbeb91998f056ade5b9c8b8
crc32: 0E3FEE04
md5: 10269f6657d20a408bff734b1887d211
sha1: 0999ad8e718e0e709d1fa8c35e84bbe0439acd70
sha256: 986290d98191d294fa6824f910276426731929525bbeb91998f056ade5b9c8b8
sha512: fe9cce365a1665aaa73612261f85b3fecd223a4b8311751a93d9347f340cb3fb61365c6127a5649a6c6833868e4657eff057138aae31bd7676a757fd262a1a68
ssdeep: 49152:+nBT6RL7GfXQT6RzL7GfX5RzNQT6RzL7GfX:+nBw7NG7LG7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D068E22B6A1C476C1A62639DE17C7E84729BD202E38D90B37F43D4F3E356476826397
sha3_384: 710de6061196466631ef402e0e84547a6c6bf1f9bbfb5dfe62f0c1c81030901ecf3f64cfe4da81f3c8c4ff1904058e3e
ep_bytes: 558bec83c4f0b86c1e4700e8c043f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Xanfpezes.E also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.Fasong.l4hb
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47522083
FireEyeGeneric.mg.10269f6657d20a40
McAfeeGenericRXQR-TK!10269F6657D2
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Bingoml.37bb4ad1
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.e718e0
BitDefenderThetaGen:NN.ZelphiF.34114.KpZ@a0tGh!nb
CyrenW32/Bingoml.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Xanfpezes.E
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Rootkit-4927
KasperskyHEUR:Trojan.Win32.Bingoml.gen
BitDefenderTrojan.GenericKD.47522083
NANO-AntivirusTrojan.Win32.Xanfpezes.ctohhu
AvastWin32:RootkitX-gen [Rtk]
TencentTrojan.Win32.Bingoml.wc
Ad-AwareTrojan.GenericKD.47522083
EmsisoftTrojan.GenericKD.47522083 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebBackDoor.Click.1197
ZillyaRootkit.Xanfpezes.Win32.19
TrendMicroTROJ_GEN.R002C0OLB21
McAfee-GW-EditionGenericRXQR-TK!10269F6657D2
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1J5BQK
JiangminRootkit.Xanfpezes.i
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2099CE
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Xanfpezes.3743692
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.R457493
Acronissuspicious
VBA32Rootkit.Xanfpezes
ALYacTrojan.GenericKD.47522083
MAXmalware (ai score=86)
MalwarebytesTrojan.Xanfpezes
TrendMicro-HouseCallTROJ_GEN.R002C0OLB21
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.GenAsa!6tKOJGQUNqA
FortinetW32/Click.1197!tr.bdr
AVGWin32:RootkitX-gen [Rtk]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Xanfpezes.E?

Win32/Xanfpezes.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment