Malware

Win32/Socks.NAJ (file analysis)

Malware Removal

The Win32/Socks.NAJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Socks.NAJ virus can do?

  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

Related domains:

dns-blabla.com
dns-blabla.net

How to determine Win32/Socks.NAJ?


File Info:

crc32: 46D184E5
md5: d1e26506cae66d7900ede58d9892689f
name: D1E26506CAE66D7900EDE58D9892689F.mlw
sha1: 62be520f571bb7602ceb201a96df73c2e24a103a
sha256: 2e7929bf2e9fd6410be7a1a460f9acb5a6d824c7a19d329a4f4ee296cd09eef0
sha512: 1b4a4315d0e2bc6220dc04f6db13556cc139b774c6566d9146c286cc5ffcd1a36aa2011c3eaa4c7912fee72e15734200ff1a9606bb3f79c8fbcf90e8cc578a49
ssdeep: 6144:QnoK0zaHdLIKbSNmvbSO0bS2AmbSYCqbSxbS3bS1TaRDi8bdbSankP+6bfbSj:7K0MhHT2LPemnDLxQ+Au
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Socks.NAJ also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.EJ
FireEyeGeneric.mg.d1e26506cae66d79
CAT-QuickHealWorm.Socks.13494
ALYacTrojan.Crypt.EJ
CylanceUnsafe
VIPREPacker.NSAnti.Gen (v)
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005662bd1 )
BitDefenderTrojan.Crypt.EJ
K7GWEmailWorm ( 005662bd1 )
Cybereasonmalicious.6cae66
BaiduWin32.Trojan-PSW.Agent.b
CyrenW32/Socks.A.gen!Eldorado
SymantecW32.Mandaph
TotalDefenseWin32/Korced!generic
APEXMalicious
ClamAVWin.Worm.Socks-8977521-0
KasperskyTrojan-Ransom.Win32.Blocker.itys
AlibabaWorm:Win32/Blocker.81074285
NANO-AntivirusTrojan.Win32.Socks.lpxw
RisingRansom.Blocker!8.12A (TFE:5:MiRWOJqqbyM)
Ad-AwareTrojan.Crypt.EJ
EmsisoftTrojan.Crypt.EJ (B)
ComodoMalware@#c447gxkoxja5
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.DownLoader.62773
ZillyaWorm.Socks.Win32.284
TrendMicroWORM_SOCKS.BL
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
MaxSecureWorm.Socks
SophosML/PE-A + Troj/Agent-BCMM
IkarusTrojan-Downloader.Win32.Small
JiangminWorm/Socks.ni
AviraTR/Crypt.ULPM.Gen
Antiy-AVLWorm/Win32.Socks
MicrosoftWorm:Win32/Autorun.gen!BS
ArcabitTrojan.Crypt.EJ
ZoneAlarmTrojan-Ransom.Win32.Blocker.itys
GDataTrojan.Crypt.EJ
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Socks.R2364
Acronissuspicious
McAfeeArtemis!D1E26506CAE6
MAXmalware (ai score=85)
VBA32SScope.Worm.Socks.afv
MalwarebytesGeneric.Worm.Autorun.DDS
ESET-NOD32a variant of Win32/Socks.NAJ
TrendMicro-HouseCallWORM_SOCKS.BL
TencentWin32.Trojan.Blocker.Wrzu
YandexTrojan.GenAsa!XFaKFzne070
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Socks.HF!worm
BitDefenderThetaAI:Packer.6E99E8311B
AVGWin32:Dh-A [Heur]
AvastWin32:Dh-A [Heur]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Ransom.0b2

How to remove Win32/Socks.NAJ?

Win32/Socks.NAJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment