Malware

JPG:MS04-028 [Expl] removal instruction

Malware Removal

The JPG:MS04-028 [Expl] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What JPG:MS04-028 [Expl] virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine JPG:MS04-028 [Expl]?


File Info:

name: E02F79D0B4D46ED1FBC4.mlw
path: /opt/CAPEv2/storage/binaries/005c3b0bb6f0352e80fada28431f0ebcd048b8389f7c633b5757df01489a27ad
crc32: 45A4A04B
md5: e02f79d0b4d46ed1fbc4ef315bf42321
sha1: 44d077b6b1e844399953fa4c12caa7e8f022ff0c
sha256: 005c3b0bb6f0352e80fada28431f0ebcd048b8389f7c633b5757df01489a27ad
sha512: 39f3aa27796b2d70daac984927a621eb776b3f50669c15c6e433684c4f839c3a0284c98735af99daf32cf013e92f42f0251a244afc7859c20541f8d5570a061a
ssdeep: 6144:2dO35Vs+UU+j7Yc5qAKChhFjvPH+bMWAOc1dBKB7Thl8fFu2bs7/VIUFMrJd:2dOpVVWTqAlhv4Mr51qZH8fI2bs7/VI/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB74E1213AE4CCBAC3931531CE546BF5E1F9DA584E21483333D44A6DAE7DA81C126F6E
sha3_384: 2089a4344ec017fbf2257968cd9fccaea5af19a58de286ac6e79b804260feb9dada0e80d5e8f1b8e2d7ae2f8fd09ca21
ep_bytes: 558bec6aff6878cd4100689693410064
timestamp: 2009-02-03 07:21:07

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z SFX
FileVersion: 4.65
InternalName: 7z.sfx
LegalCopyright: Copyright (c) 1999-2009 Igor Pavlov
OriginalFilename: 7z.sfx.exe
ProductName: 7-Zip
ProductVersion: 4.65
Translation: 0x0409 0x04b0

JPG:MS04-028 [Expl] also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Exploit.ANUA
FireEyeTrojan.Exploit.ANUA
CAT-QuickHealJPEG.Exploit.ms04-028
McAfeeArtemis!E02F79D0B4D4
CylanceUnsafe
SangforVirus.DOC.Sugar.A
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaVirus:Office97/Sugar.a1f26d09
K7GWMacro ( 0008c4a21 )
K7AntiVirusMacro ( 0008c4a21 )
CyrenW32/Ndie.2168
SymantecTrojan.Gen.6
ESET-NOD32multiple detections
BaiduMSExcel.Virus.Sugar.a
TrendMicro-HouseCallTROJ_XPLOIT.SBG
Paloaltogeneric.ml
KasperskyExploit.Win32.MS04-028.am
BitDefenderTrojan.Exploit.ANUA
NANO-AntivirusVirus.Macro.Sugar.inz
AvastJPG:MS04-028 [Expl]
TencentWin32.Exploit.Ms04-028.Agax
EmsisoftTrojan.Exploit.ANUA (B)
ComodoMalware@#3726sow1tpqey
DrWebWin32.NeverDie.2168
ZillyaDownloader.OpenConnection.JS.81668
TrendMicroTROJ_XPLOIT.SBG
McAfee-GW-EditionBehavesLike.Win32.Virus.fc
SentinelOneStatic AI – Malicious SFX
SophosMal/Generic-R
APEXMalicious
GDataVBA:Logan.1415
JiangminX97M/Sugar.a
AviraEXP/MS04-028.JPEG.A
KingsoftWin32.Infected.AutoInfector.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win32/Never_Die
VBA32Exploit.JPG
ALYacVBA:Logan.1415
MAXmalware (ai score=100)
MalwarebytesMalware.AI.499089275
RisingMacro.Sugar (CLASSIC:bWQ1Oqn751vBYPb09sUG7MYJCo0)
YandexExploit.MS04-028
IkarusExploit.Win32.MS04
MaxSecureTrojan.Malware.9973460.susgen
FortinetData/MS04028.fam!exploit
AVGJPG:MS04-028 [Expl]
PandaTrj/CI.A

How to remove JPG:MS04-028 [Expl]?

JPG:MS04-028 [Expl] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment