Malware

Win32.XPaj.B (file analysis)

Malware Removal

The Win32.XPaj.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.XPaj.B virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32.XPaj.B?


File Info:

name: F39C8C6FB716E49022CD.mlw
path: /opt/CAPEv2/storage/binaries/052cad3e007f7803acafa31c727f1708173176e87d761f13990b02a28971d3fa
crc32: D38A9233
md5: f39c8c6fb716e49022cd773967ed1c13
sha1: 421562b66d7ad3e6b176471db2da0d7ca26174ee
sha256: 052cad3e007f7803acafa31c727f1708173176e87d761f13990b02a28971d3fa
sha512: 9820bcb4f22d95e7b7bfb5d3e519383f2b960a5ec062ba5f42727080f60ebd4ec246ecdb09919b515b80ba7a742e6e78acc9020fa1f61ffa04249a589509bd20
ssdeep: 3072:QVCBEqlmFESJqC0uP9Yx81YURbSI1duHoaYCmoi8ihpf4OwIuXBJ5gcnh93nr:6CLgFE8VP9Y82IuihpfDI5Fnr
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16D24CF133F8210B1D2C801753AEAF777DE3078715F2482E3E750AE69A9745D1A6BE34A
sha3_384: b6d89753cf27aa98005c5da00dce3d2b0aef4ceeaa199d38e269253cc0cbfd0e79b5c7b7012e0407e2d8bd8c61c3156b
ep_bytes: e8ae040000e978feffffcccccccccccc
timestamp: 2011-09-24 17:39:29

Version Info:

CompanyName: Microsoft Corporation
FileDescription: DTDUMP.EXE
FileVersion: 10.0.17134.1304 (WinBuild.160101.0800)
InternalName: DTDUMP.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: DTDUMP.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1304
Translation: 0x0409 0x04b0

Win32.XPaj.B also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Xpaj.n!c
DrWebWin32.Goblin
MicroWorld-eScanWin32.XPaj.B
ClamAVWin.Trojan.Xpaj-2
FireEyeGeneric.mg.f39c8c6fb716e490
CAT-QuickHealW32.Xpaj.A
SkyhighBehavesLike.Win32.Expiro.dc
Cylanceunsafe
VIPREWin32.XPaj.B
SangforVirus.Win32.Xpaj.Vl0n
K7AntiVirusVirus ( 005ab3521 )
AlibabaVirus:Win32/Goblin.a4575bf2
K7GWVirus ( 005ab3521 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:FileInfector.EA694EEA0C
SymantecW32.Xpaj.C
Elasticmalicious (high confidence)
ESET-NOD32Win32/Goblin.A.Gen
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Goblin.gen
BitDefenderWin32.XPaj.B
NANO-AntivirusVirus.Win32.Goblin.bcufsv
AvastWin32:Goblin
TencentVirus.Win32.Goblin.ka
EmsisoftWin32.XPaj.B (B)
F-SecureMalware.W32/Xpaj.A
BaiduWin32.Virus.Xpaj.gen
ZillyaTrojan.XPaj.Win32.286
TrendMicroPE_XPAJ.A-1
Trapminesuspicious.low.ml.score
SophosMal/Xpaj-A
SentinelOneStatic AI – Malicious PE
GDataWin32.XPaj.B
GoogleDetected
AviraW32/Xpaj.A
Antiy-AVLVirus/Win32.Goblin.a
ArcabitWin32.XPaj.B
ZoneAlarmVirus.Win32.Goblin.gen
MicrosoftVirus:Win32/Xpaj.gen!A
VaristW32/Goblin.A.gen!Eldorado
AhnLab-V3Win32/Xpaj
ALYacWin32.XPaj.B
MAXmalware (ai score=84)
MalwarebytesXpaj.Virus.FileInfector.DDS
PandaTrj/Chgt.AC
TrendMicro-HouseCallPE_XPAJ.A-1
IkarusVirus.Win32.Xpaj
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Goblin.A
AVGWin32:Goblin
DeepInstinctMALICIOUS

How to remove Win32.XPaj.B?

Win32.XPaj.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment