Worm

Net-Worm.Win32.Kolab.aetg malicious file

Malware Removal

The Net-Worm.Win32.Kolab.aetg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Net-Worm.Win32.Kolab.aetg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Net-Worm.Win32.Kolab.aetg?


File Info:

name: 95609625FEE4AE7816C3.mlw
path: /opt/CAPEv2/storage/binaries/8d7fab9c0787966069049b778980de9358abba2104e6fb9f984133e02958846d
crc32: BCD4B467
md5: 95609625fee4ae7816c3d60d3e98eb4c
sha1: 2a31844a73e5f3c3f90ecf0748b642cb74e420d3
sha256: 8d7fab9c0787966069049b778980de9358abba2104e6fb9f984133e02958846d
sha512: 933cdd954eca7ca269bb52d9030c884690060d86d75aac6b4440a05f38136606c796eadc3d4e4b3dbc09f08846a157bf06b074688f2cd97c49d3bb95e2d47fba
ssdeep: 3072:8CmfaxDN8Le/uJ36x0/Nui2IJGcu/xc3xQfCjrbJiXFQ:8CDuXJk0/0pI0cqxc21
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180D3129277BD40D3F3527A37265EA2BF3634EDB4C77E8A2F1B529601AF5300E2484625
sha3_384: 2d500a4c4e6b8c00a2919a558b914c8ccd56ef6988a16411a5a4f6ba340a6b41130fd40fdac08b890c2dcbc0f998b02f
ep_bytes: 60be153041008dbeebdffeff57eb0b90
timestamp: 2005-12-05 08:37:04

Version Info:

CompanyName: Ylqmiyueq Juugoq
FileDescription: Ylqmiyueq Tlxlbnb Tyfcbqfhbi
FileVersion: 114,91,91,125
InternalName: Ylqmiyueq
LegalCopyright: Copyright © Ylqmiyueq Juugoq 2002-2009
OriginalFilename: Ylqmiyueq.exe
ProductName: Ylqmiyueq Tlxlbnb Tyfcbqfhbi
ProductVersion: 7,40,64,56
Translation: 0x0409 0x04e4

Net-Worm.Win32.Kolab.aetg also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicWorm.Win32.Kolab.p!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.95609625fee4ae78
CAT-QuickHealWorm.SlenfBot.Gen
ALYacGen:Heur.VIZ.!e!.1
CylanceUnsafe
VIPREBackdoor.Win32.Qakbot.ax (v)
SangforTrojan.Win32.Generic.5
K7AntiVirusTrojan ( f1000f011 )
AlibabaWorm:Win32/Kolab.03f2de5e
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.5fee4a
VirITTrojan.Win32.Generic.AZMI
CyrenW32/Zbot.CN.gen!Eldorado
SymantecW32.Qakbot!gen5
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.FakeAV-4880
KasperskyNet-Worm.Win32.Kolab.aetg
BitDefenderGen:Heur.VIZ.!e!.1
NANO-AntivirusTrojan.Win32.Kolab.haspq
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Rn]
MicroWorld-eScanGen:Heur.VIZ.!e!.1
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114de3c1
Ad-AwareGen:Heur.VIZ.!e!.1
EmsisoftGen:Heur.VIZ.!e!.1 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
DrWebTrojan.Packed.21467
ZillyaTrojan.FakeAV.Win32.48326
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionBehavesLike.Win32.MultiDropper.cc
SophosML/PE-A + Troj/FakeAV-CUH
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VIZ.!e!.1
JiangminTrojanSpy.Zbot.avxr
WebrootW32.Malware.Downloader
AviraTR/Spy.Zbot.HH
Antiy-AVLTrojan/Generic.ASMalwS.548CA9
KingsoftWorm.Kolab.ae.(kcloud)
ArcabitTrojan.VIZ.!e!.1
ViRobotWorm.Win32.A.Net-Kolab.135680.B
ZoneAlarmNet-Worm.Win32.Kolab.aetg
MicrosoftPWS:Win32/Zbot.gen!Y
AhnLab-V3Trojan/Win32.Zbot.R3226
McAfeeW32/Pinkslipbot.gen.af
MAXmalware (ai score=99)
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallBKDR_QAKBOT.SMG
RisingWorm.Kolab!8.1C4D (CLOUD)
YandexTrojanSpy.Zbot!qiwFZ1xhTHA
IkarusBackdoor.Win32.Rbot
MaxSecureTrojan.Malware.1728868.susgen
FortinetW32/Kryptik.NAS!tr
BitDefenderThetaGen:NN.ZexaF.34212.imKfaCrtSobc
AVGWin32:Malware-gen
PandaBck/Qbot.AO

How to remove Net-Worm.Win32.Kolab.aetg?

Net-Worm.Win32.Kolab.aetg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment