Worm

About “Fearso.Worm.Agent.DDS” infection

Malware Removal

The Fearso.Worm.Agent.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fearso.Worm.Agent.DDS virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Fearso.Worm.Agent.DDS?


File Info:

name: 31AC9BD237DF55BD7210.mlw
path: /opt/CAPEv2/storage/binaries/615c6a1b080334be7713fd55f3e4ea75396afa75a1e1e70d66af048784838f73
crc32: FE368E5A
md5: 31ac9bd237df55bd721009bde06368a6
sha1: f92575350744b1117a5a879712f7536f93a15819
sha256: 615c6a1b080334be7713fd55f3e4ea75396afa75a1e1e70d66af048784838f73
sha512: 2245d55dc9d089961902111a1296f6e194d2e9e63bea75c2cfbf957d6c77e165b556a51a83602498fd5025b382430c025de92e968d625a52be9a43a020578756
ssdeep: 1536:gwmunBjqs32bxPpBRy32Z6gJlyiKqVo6p3e:3munBjTmbxRBRN6WYiKqVo6pu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117B35C96EAC1887BD0300DBCAC4BD6A4B87FBA303D3528D279E91F4C59BC1D15A2D953
sha3_384: 0e24e8c4c94be2e774162ff0f759aac2ac019866a595548d956f882f6bbf72ade0721c43ce5351a128369bcf51b03db9
ep_bytes: 0f84e20000006a4758ffd6ab8b426803
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Fearso.Worm.Agent.DDS also known as:

LionicWorm.Win32.Fearso.l2D1
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Malware.FMPfV!p2p!u.D1DA489B
ClamAVWin.Worm.Fearso-6840756-0
ALYacDeepScan:Generic.Malware.FMPfV!p2p!u.D1DA489B
Cylanceunsafe
VIPREDeepScan:Generic.Malware.FMPfV!p2p!u.D1DA489B
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Basine.b22192cf
BaiduWin32.Worm.Farex.a
CyrenW32/LdPinch.N.gen!Eldorado
SymantecW32.Nofer.A@mm
ESET-NOD32a variant of Generik.LOZUEWK
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AvastWin32:Fearso-W [Wrm]
F-SecureDropper.DR/Patched.Ren.Gen
DrWebTrojan.AVKill.9837
TrendMicroTROJ_GEN.R03BC0OD423
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.31ac9bd237df55bd
SophosMal/Basine-C
GDataWin32.Trojan.Agent.9UR167
AviraDR/Patched.Ren.Gen
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Win-Trojan/Hupigon.Gen
McAfeeArtemis!31AC9BD237DF
MalwarebytesFearso.Worm.Agent.DDS
TrendMicro-HouseCallTROJ_GEN.R03BC0OD423
RisingTrojan.Generic@AI.100 (RDML:UUXsa94351MMa49sMve5ew)
IkarusEmail-Worm.Win32.Fearso.C
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZexaF.36132.gGY@a0WjUoaG
AVGWin32:Fearso-W [Wrm]
DeepInstinctMALICIOUS

How to remove Fearso.Worm.Agent.DDS?

Fearso.Worm.Agent.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment