Malware

About “Win32:Goblin” infection

Malware Removal

The Win32:Goblin is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Goblin virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32:Goblin?


File Info:

name: AE91A80D21D80492C24E.mlw
path: /opt/CAPEv2/storage/binaries/de3b3c7571be2dca4303d3ec4dc19d9d61b0464c5630c71e353e7fe6664ba6ee
crc32: 86F9D336
md5: ae91a80d21d80492c24e6a1bff13c34f
sha1: ea2d7d53d10ea3614090deb1a6a471fa1b66d96f
sha256: de3b3c7571be2dca4303d3ec4dc19d9d61b0464c5630c71e353e7fe6664ba6ee
sha512: ddc352ef1547f1f77b96b352bbc248799219c0b110ccf63aac19564a14a07fb90dfc67bc2a3afcebfabe92bf4c4a9c02740dcee673d44ac2eb1551daafca8580
ssdeep: 6144:oDMOXBYV6A1Y/X+tmfTYYsNYlH7GFiihp0f/J:OMOXBeFakmMnNY97GsXJ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1AD44AE027B855C31C2A3247027A9F736DE749E328B1981C3A372DE66B9351D2763D78B
sha3_384: 5f180d0e2b9cebd2cedd424ff40744e3ee4e2b372ee23ff7fe48f63004fdd773909e2f8df2714bc29a1fb2cbaf44c939
ep_bytes: 8bff558bec837d0c017505e8b3050000
timestamp: 2002-03-10 03:32:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectMusic Style Engline
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: Microsoft DirectMusic Style Engline
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dmstyle.dll
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Win32:Goblin also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Xpaj.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.ae91a80d21d80492
CAT-QuickHealW32.Xpaj.A
SkyhighBehavesLike.Win32.Trojan.dc
McAfeeArtemis!AE91A80D21D8
Cylanceunsafe
SangforVirus.Win32.Xpaj.Vvdp
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Goblin.8c12c0f8
K7GWVirus ( 005ab3521 )
K7AntiVirusVirus ( 005ab3521 )
BaiduWin32.Virus.Xpaj.gen
SymantecW32.Xpaj.C
ESET-NOD32Win32/Goblin.A.Gen
APEXMalicious
ClamAVWin.Trojan.Xpaj-2
KasperskyVirus.Win32.Goblin.gen
BitDefenderWin32.XPaj.B
NANO-AntivirusVirus.Win32.Goblin.bcufsv
MicroWorld-eScanWin32.XPaj.B
AvastWin32:Goblin
TencentVirus.Win32.Goblin.ka
EmsisoftWin32.XPaj.B (B)
F-SecureMalware.W32/Xpaj.A
DrWebWin32.Goblin
VIPREWin32.XPaj.B
TrendMicroPE_XPAJ.A-1
SophosMal/Xpaj-A
IkarusVirus.Win32.Xpaj
VaristW32/Goblin.B.gen!Eldorado
AviraW32/Xpaj.A
Antiy-AVLVirus/Win32.Goblin.a
MicrosoftVirus:Win32/Xpaj.gen!A
ArcabitWin32.XPaj.B
ZoneAlarmVirus.Win32.Goblin.gen
GDataWin32.XPaj.B
GoogleDetected
AhnLab-V3Win32/Xpaj
ALYacWin32.XPaj.B
MAXmalware (ai score=86)
MalwarebytesXpaj.Virus.FileInfector.DDS
PandaTrj/Chgt.AC
TrendMicro-HouseCallPE_XPAJ.A-1
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Goblin.A
BitDefenderThetaAI:FileInfector.EA694EEA0C
AVGWin32:Goblin
DeepInstinctMALICIOUS

How to remove Win32:Goblin?

Win32:Goblin removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment