Categories: Worm

Email-Worm.Win32.Gigex malicious file

The Email-Worm.Win32.Gigex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Email-Worm.Win32.Gigex virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates RWX memory
  • Terminates another process
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Harvests information related to installed mail clients

How to determine Email-Worm.Win32.Gigex?


File Info:

name: DE23992FB1E3F60AB39D.mlwpath: /opt/CAPEv2/storage/binaries/f961a24c298665cc23173073c691bc4a28c31f0b18caaad24cc101e7d8e40173crc32: A5DA397Dmd5: de23992fb1e3f60ab39dfaa4c93a72d6sha1: a952b26078aa041bf5663ffb3a0ac974468bea9asha256: f961a24c298665cc23173073c691bc4a28c31f0b18caaad24cc101e7d8e40173sha512: ad8122305b4300d167b2e465936a1e6a23bbb4028e97f3f3a8220e79f18d111c1871de2bbecc43094de7cc0ff66aef15972aae831d4aa77d968b843ad1ac6c9assdeep: 768:6KGTwyyafTvjEaEWwV3auUCezON+3I8+1z:6lwyyiTLEaEWIa3ChI+1type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T1A50348FB7AA1E595FCC452F04AB48C8DF774B81636A390EF26B877460E1B834741246Asha3_384: e077e290953ae245b8b7d79cddc4dd3dd3b32ea2fffc0ebe65f32ffd45134f506cfa93cd1a99d818fa8a6d6a3ea29a44ep_bytes: 6683cf00fc9083c300eb01e690fc90fctimestamp: 2002-08-30 14:18:48

Version Info:

0: [No Data]

Email-Worm.Win32.Gigex also known as:

Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Generic.Malware.GJMePfPk!16g.B31FF682
FireEye Generic.mg.de23992fb1e3f60a
McAfee W32/Gink@MM
Cylance Unsafe
VIPRE Generic.Malware.GJMePfPk!16g.B31FF682
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005581461 )
BitDefender Generic.Malware.GJMePfPk!16g.B31FF682
K7GW Trojan ( 005581461 )
Cybereason malicious.fb1e3f
Cyren W32/Gigex.A.gen!Eldorado
Symantec W32.Gink.Worm
ESET-NOD32 Win32/Gigex.A
APEX Malicious
Kaspersky Email-Worm.Win32.Gigex
Avast Win32:Evo-gen [Susp]
Rising Worm.Gigex.s (CLASSIC)
Ad-Aware Generic.Malware.GJMePfPk!16g.B31FF682
Emsisoft Generic.Malware.GJMePfPk!16g.B31FF682 (B)
Comodo Worm.Win32.Gigex.A@8f3nxw
DrWeb Win32.HLLM.Gigu.24608
TrendMicro WORM_UGIG.B
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.nt
Trapmine malicious.high.ml.score
Sophos ML/PE-A + W32/Gigex-A
Ikarus Worm.Win32.Gigex
Jiangmin Worm.Gigex.aed
Avira WORM/Rbot.Gen
Antiy-AVL Trojan/Generic.ASMalwS.120F
Microsoft Worm:Win32/Gigex.A@mm
ZoneAlarm Email-Worm.Win32.Gigex
GData Generic.Malware.GJMePfPk!16g.B31FF682
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.HDC.R476052
Acronis suspicious
BitDefenderTheta AI:FileInfector.6541C4AD10
ALYac Generic.Malware.GJMePfPk!16g.B31FF682
MAX malware (ai score=81)
VBA32 Packed.Krap
Malwarebytes Worm.Giga
TrendMicro-HouseCall WORM_UGIG.B
Tencent Email-Worm.Win32.Gigex.ha
Yandex Trojan.GenAsa!ei8CZizcGto
SentinelOne Static AI – Malicious PE
Fortinet W32/Gigex.A@mm
AVG Win32:Evo-gen [Susp]
Panda Trj/Genetic.gen
CrowdStrike win/malicious_confidence_100% (D)

How to remove Email-Worm.Win32.Gigex?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Win32/AutoRun.VB.TP removal instruction

The Win32/AutoRun.VB.TP is considered dangerous by lots of security experts. When this infection is active,…

1 min ago

Trojan.MauvaiseRI.S5242943 information

The Trojan.MauvaiseRI.S5242943 is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

Zusy.297198 (B) information

The Zusy.297198 (B) is considered dangerous by lots of security experts. When this infection is…

7 mins ago

Should I remove “Trojan.Win32.Agent.xbnair”?

The Trojan.Win32.Agent.xbnair is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Malware.AI.3088816149 removal

The Malware.AI.3088816149 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

About “Trojan.Generic.35804723” infection

The Trojan.Generic.35804723 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago