Worm

Win32.Worm.Socks.G (B) removal tips

Malware Removal

The Win32.Worm.Socks.G (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.Socks.G (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32.Worm.Socks.G (B)?


File Info:

name: EADA7F4C5EE798FE29E7.mlw
path: /opt/CAPEv2/storage/binaries/6442cd166e5685b1b9e96f6ceb1dff61d35e03cb248b79ac234d38ffe4347cf4
crc32: 134317AE
md5: eada7f4c5ee798fe29e75f77e0886b90
sha1: bd9293eef14a6bbf00e5fa2395aea71dfd6662f6
sha256: 6442cd166e5685b1b9e96f6ceb1dff61d35e03cb248b79ac234d38ffe4347cf4
sha512: 236badedc2f2d1f37428a3fe2896f3328f59a702e462dca0fafe45f5ecb900b7ac2f139c3aabfe140104925bf2be5edd8f6f874e0f265f3f8c9e0ac4ece64aee
ssdeep: 384:V3c7uPDysvAsAwcXbjnEurTQhQL1c7uPD3NZ23jizBMB:9NPGsvAsAw8/EAQh6NPhfA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EBC33A9D7746EE3AC0D108F11F224416BFBEFEA045A85B03CB84528E08B29D5E37964E
sha3_384: 7507d21bb473866d641de23c1fb0b3105e14187a796bfb6fdd848934c61c03b2a94d0d1c6a16df3a28752f03e6d1e875
ep_bytes: 558bec6aff68288640006870a3400064
timestamp: 2008-03-30 15:20:09

Version Info:

0: [No Data]

Win32.Worm.Socks.G (B) also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Worm.Socks.G
ClamAVWin.Worm.Socks-4
SkyhighBackDoor-DOQ
McAfeeBackDoor-DOQ
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Socks.Win32.856
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.ef14a6
BaiduWin32.Trojan-PSW.Agent.e
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/PSW.Agent.NHI
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Socks.au
BitDefenderWin32.Worm.Socks.G
NANO-AntivirusTrojan.Win32.Socks.wsiw
AvastWin32:Socks-F [Wrm]
TencentWorm.WIn32.Socks.zda
SophosW32/Socks-H
F-SecureWorm.WORM/Socks.AU.166
DrWebWin32.HLLW.Socks
VIPREWin32.Worm.Socks.G
TrendMicroWORM_SOCKS.EJ
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.eada7f4c5ee798fe
EmsisoftWin32.Worm.Socks.G (B)
IkarusTrojan-Dropper.Agent
GDataWin32.Worm.Socks.G
JiangminWorm/Socks.t
WebrootW32.Malware.Gen
GoogleDetected
AviraWORM/Socks.AU.166
Antiy-AVLWorm/Win32.Socks
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.PSW.Agent.NHI@c49c
ArcabitWin32.Worm.Socks.G
ZoneAlarmWorm.Win32.Socks.au
MicrosoftBackdoor:Win32/Koceg.gen!A
VaristW32/Socks.B.gen!Eldorado
AhnLab-V3Worm/Win.Socks.R604306
Acronissuspicious
VBA32SScope.Worm.Socks.afv
ALYacWin32.Worm.Socks.G
MAXmalware (ai score=80)
Cylanceunsafe
PandaW32/Socks.B.worm
TrendMicro-HouseCallWORM_SOCKS.EJ
RisingWorm.Socks!1.C134 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Socks.NAK!tr
BitDefenderThetaAI:Packer.7BE35C251E
AVGWin32:Socks-F [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32.Worm.Socks.G (B)?

Win32.Worm.Socks.G (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment