Worm

UDS:Worm.Win32.Socks.r (file analysis)

Malware Removal

The UDS:Worm.Win32.Socks.r is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Worm.Win32.Socks.r virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine UDS:Worm.Win32.Socks.r?


File Info:

name: 3061E3F905B645308B6B.mlw
path: /opt/CAPEv2/storage/binaries/12273f27edc17c002b9099dcbd9885a848fed7d74e63c82201022bc27163db49
crc32: E5A10784
md5: 3061e3f905b645308b6b7e115a52a848
sha1: d256d61e1fd8967c5191b637eece6a113f483a9e
sha256: 12273f27edc17c002b9099dcbd9885a848fed7d74e63c82201022bc27163db49
sha512: c5cfcbbfaee16cde917a87222dce8aaa4f5295d46207a9c1fcb24f21cbed705b4f34a69cfe59ca5a6221b6fed4798144d1d118719dbe319051cd9a19ababb2f4
ssdeep: 1536:tTIG/ZhdM1WI3ZnQbuCyRWhiPh8s/aC2X:tT7/ZhdM1WI3ZnQbuCwVaC2X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0547D56F641DA36C9C204F2373909A7F67EFC386DA56213DB89064EAEE0DC7A250317
sha3_384: 813c0472e51beb2d48564640ebeb5947b6c7194fc0ae2449be42fd6792416a6259138f8f84131f84035ef94a487cbe83
ep_bytes: 00000000000000000000000000000000
timestamp: 2008-02-10 16:59:15

Version Info:

0: [No Data]

UDS:Worm.Win32.Socks.r also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Socks.o!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.3061e3f905b64530
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Socks.Win32.1025
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 00584baa1 )
AlibabaBackdoor:Win32/Koceg.96ca5ae2
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.e1fd89
BaiduWin32.Trojan-PSW.Agent.e
CyrenW32/Agent.GIA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
ClamAVWin.Worm.Socks-9
KasperskyUDS:Worm.Win32.Socks.r
AvastWin32:LdPinch-AIH [Trj]
DrWebTrojan.DownLoader.44897
TrendMicroTROJ_GEN.R03BC0DF823
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
Antiy-AVLWorm/Win32.Socks
ZoneAlarmUDS:Worm.Win32.Socks.r
MicrosoftBackdoor:Win32/Koceg.gen!A
GoogleDetected
Acronissuspicious
McAfeeArtemis!3061E3F905B6
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0DF823
RisingBackdoor.Koceg!8.877 (CLOUD)
IkarusBackdoor.Win32.Koceg
MaxSecureTrojan.Malware.208539978.susgen
FortinetW32/Koceg.S!tr
AVGWin32:LdPinch-AIH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove UDS:Worm.Win32.Socks.r?

UDS:Worm.Win32.Socks.r removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment