Malware

Win32.Murofet.A (file analysis)

Malware Removal

The Win32.Murofet.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Murofet.A virus can do?

  • Executable code extraction
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32.Murofet.A?


File Info:

crc32: AEFC0019
md5: bcb8297da56887f502372c6d91d50930
name: BCB8297DA56887F502372C6D91D50930.mlw
sha1: aec7c3ae8fee1c93f7d231fb9d7c263f0f5db0d2
sha256: 7211588f97c4f5c4bcd1ae69d9597e7f53ee1ef60f2c5deb988966d528f97d00
sha512: de72dbdca88651ee79ad98d03c131a718fba107f95dba5ec0bac16d060d8f0a47e4693fe159c1919af6d5bb8a0e58bc9c11fb2a2ccdd3d22be8b7276abdd1f98
ssdeep: 3072:fsu8L79GO3oQiibsJn537s++NwKmRmvFVboOiLVjP1k/Kp:Uug79j3oQiibsJnh+NwKmRuVUHVL2Sp
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, PECompact2 compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: Win
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Win
ProductVersion: 1.00
OriginalFilename: Win.exe

Win32.Murofet.A also known as:

BkavW32.Licat.PE
K7AntiVirusVirus ( 0040fa811 )
Elasticmalicious (high confidence)
DrWebWin32.Panda
CynetMalicious (score: 100)
CAT-QuickHealW32.Murofet.A
ALYacWin32.Murofet.A
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Murofet.31ca860c
K7GWVirus ( 0040fa811 )
Cybereasonmalicious.da5688
BaiduWin32.Virus.Murofet.a
CyrenW32/Murofet.A
SymantecTrojan.Zbot.B!inf
ESET-NOD32Win32/TrojanDownloader.Small.PAC
APEXMalicious
AvastWin32:Patched-RR [Trj]
ClamAVWin.Trojan.Murofet-1
KasperskyVirus.Win32.Murofet.a
BitDefenderWin32.Murofet.A
NANO-AntivirusVirus.Win32.Nimnul.bhskb
MicroWorld-eScanWin32.Murofet.A
TencentTrojan.Win32.VB.tlc
Ad-AwareWin32.Murofet.A
SophosMal/Generic-R + W32/Murofet-A
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
BitDefenderThetaAI:FileInfector.A399AEAE0F
VIPREVirus.Win32.Murofet.a (v)
TrendMicroPE_LICAT.SM
McAfee-GW-EditionBehavesLike.Win32.Swisyn.dh
FireEyeGeneric.mg.bcb8297da56887f5
EmsisoftWin32.Murofet.A (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.anuk
AviraW32/Murofet.A
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASVirus.69
KingsoftHeur.SSC.2667289.1216.(kcloud)
MicrosoftVirus:Win32/Zbot.B
GDataWin32.Murofet.A
AhnLab-V3Win32/Murofet
Acronissuspicious
McAfeeW32/Zbot.gen.b
MAXmalware (ai score=89)
VBA32Virus.Win32.Murofet.A
MalwarebytesBackdoor.Agent.Generic
PandaGeneric Malware
TrendMicro-HouseCallPE_LICAT.SM
RisingTrojan.VB!1.6519 (CLASSIC)
YandexTrojan.GenAsa!dm5qTke+fEg
IkarusTrojan.Win32.VB
MaxSecureVirus.W32.Murofet.A
FortinetW32/Murofet.A
AVGWin32:Patched-RR [Trj]
Paloaltogeneric.ml

How to remove Win32.Murofet.A?

Win32.Murofet.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment