Malware

Win32.XPaj.B information

Malware Removal

The Win32.XPaj.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.XPaj.B virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Binary compilation timestomping detected
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32.XPaj.B?


File Info:

name: DE132E782DFAABEEED64.mlw
path: /opt/CAPEv2/storage/binaries/8f5342b1f20d7834430c2ea66fb1369e1c5746538eee2359ba5b462459155b43
crc32: 8FFC3487
md5: de132e782dfaabeeed64884e004dc76f
sha1: 0bbb50dd1208fd01713e754c14ffab36829f3855
sha256: 8f5342b1f20d7834430c2ea66fb1369e1c5746538eee2359ba5b462459155b43
sha512: ccb458717cd560eb413a54a5fda7d12d63bf125559e4cf86dfdf3a1ecd4a89270777beac7c60453fb9ee529eae04b3343057d32f1fb642de04351ca7d382d343
ssdeep: 12288:NdqHZ44YUoGf+bwSMBW807psFcCP4MyVuOqO3SgI8:mHZVYUoGf8wJBWb7psdPLO3VI
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T149057D51B6E501F1E6DB3172390C363A857D98F8AF6482CBE3A07BA6EDA47D0D132705
sha3_384: 81ab6f190fe9423fda89f48d9442fac354916221bdf633eb96c7dde2b152779a129c89ed7597cc636cf7359646ef3192
ep_bytes: 8bff558bec837d0c017505e8f6030000
timestamp: 2093-09-29 22:57:16

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft RemoteFX OpenGL
FileVersion: 10.0.10011.16384
InternalName: rdvgogl32.dll
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: rdvgogl32.dll
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.10011.16384
Translation: 0x0409 0x04b0

Win32.XPaj.B also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Xpaj.n!c
MicroWorld-eScanWin32.XPaj.B
ClamAVWin.Trojan.Xpaj-2
FireEyeWin32.XPaj.B
CAT-QuickHealW32.Xpaj.A
SkyhighBehavesLike.Win32.Ramnit.ch
ALYacWin32.XPaj.B
MalwarebytesXpaj.Virus.FileInfector.DDS
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Goblin.1c4ba71d
K7GWVirus ( 005ab3521 )
K7AntiVirusVirus ( 005ab3521 )
ArcabitWin32.XPaj.B
BitDefenderThetaAI:FileInfector.EA694EEA0C
SymantecW32.Xpaj.C
Elasticmalicious (high confidence)
ESET-NOD32Win32/Goblin.A.Gen
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Goblin.gen
BitDefenderWin32.XPaj.B
NANO-AntivirusVirus.Win32.Goblin.bcufsv
AvastWin32:Goblin
TencentVirus.Win32.Goblin.kc
EmsisoftWin32.XPaj.B (B)
BaiduWin32.Virus.Xpaj.gen
F-SecureMalware.W32/Xpaj.A
DrWebWin32.Goblin
VIPREWin32.XPaj.B
TrendMicroPE_XPAJ.A-1
SophosMal/Xpaj-A
IkarusVirus.Win32.Xpaj
GoogleDetected
AviraW32/Xpaj.A
Antiy-AVLVirus/Win32.Goblin.a
MicrosoftVirus:Win32/Xpaj.gen!A
ZoneAlarmVirus.Win32.Goblin.gen
GDataWin32.XPaj.B
VaristW32/Xpaj.A.gen!Eldorado
AhnLab-V3Win32/Xpaj
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPE_XPAJ.A-1
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Goblin.A
AVGWin32:Goblin
DeepInstinctMALICIOUS

How to remove Win32.XPaj.B?

Win32.XPaj.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment