Malware

Win32:Socks-F [Wrm] information

Malware Removal

The Win32:Socks-F [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Socks-F [Wrm] virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32:Socks-F [Wrm]?


File Info:

name: D96E6B4751BCF3B0AEE4.mlw
path: /opt/CAPEv2/storage/binaries/f36f25ba7d142d297805d94b78f71a84a979606957648001f4d7216b97d336c0
crc32: 55EF55B4
md5: d96e6b4751bcf3b0aee41c8a26e6cad6
sha1: 2d4ad5c6327ee5ce240c5ebb51c2419d8d7f4fd8
sha256: f36f25ba7d142d297805d94b78f71a84a979606957648001f4d7216b97d336c0
sha512: 57b45cabfec2b9bbf23e7cd1fc79a748b29806de6c3a92408945e74082733cc99665a11353f66877530714f164a5183c0e499f5450b5f4b984762c9263587e34
ssdeep: 6144:9bmzK/QbS5fY7PasbSxbSsryP/B+1+ycbSeDiDcD0dbShiMEfRbS0mcf6/B+ybSj:heK/a4f0aOe4hy+3DiDjxZHfNzm+EZu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A64021E5782E930FED20BFA1A463815AD7E738069A7D5B08351D7EB4D1BEC2F22049D
sha3_384: b0b46d239ad74e45baf8c417555c224402b5908ae6f5b6a97150d782c08727fc246a56f5115985160aaf8cf74b9af202
ep_bytes: 558bec6aff68288640006870a3400064
timestamp: 2008-03-30 15:20:09

Version Info:

0: [No Data]

Win32:Socks-F [Wrm] also known as:

BkavW32.FamVT.SockTTc.Worm
MicroWorld-eScanTrojan.Crypt.EJ
ClamAVWin.Worm.Socks-4
FireEyeGeneric.mg.d96e6b4751bcf3b0
CAT-QuickHealTrojan.Toga.26581
McAfeeBackDoor-DOQ
MalwarebytesGeneric.Spyware.Stealer.DDS
VIPRETrojan.Crypt.EJ
SangforSuspicious.Win32.Save.ins
K7AntiVirusPassword-Stealer ( 000345c61 )
K7GWPassword-Stealer ( 000345c61 )
Cybereasonmalicious.751bcf
BitDefenderThetaAI:Packer.CEF2DCA81B
CyrenW32/Socks.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/PSW.Agent.NHI
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Socks.au
BitDefenderTrojan.Crypt.EJ
NANO-AntivirusTrojan.Win32.Socks.wsiw
SUPERAntiSpywareTrojan.Agent/Gen-PWS
AvastWin32:Socks-F [Wrm]
EmsisoftTrojan.Crypt.EJ (B)
BaiduWin32.Trojan-PSW.Agent.e
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Socks
ZillyaWorm.Socks.Win32.13
TrendMicroWORM_SOCKS.EA
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fc
Trapminemalicious.high.ml.score
SophosW32/Socks-H
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.17C63S7
JiangminWorm/Socks.t
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.Socks
XcitiumTrojWare.Win32.PSW.Agent.NHI@c49c
ArcabitTrojan.Crypt.EJ
ViRobotTrojan.Win32.Agent.120109
ZoneAlarmWorm.Win32.Socks.au
MicrosoftBackdoor:Win32/Koceg.gen!A
GoogleDetected
AhnLab-V3Worm/Win32.Socks.R2364
VBA32SScope.Worm.Socks.afv
MAXmalware (ai score=86)
Cylanceunsafe
PandaW32/Socks.B.worm
TrendMicro-HouseCallWORM_SOCKS.EA
RisingWorm.Socks!1.C134 (CLASSIC)
YandexTrojan.GenAsa!G4X970vdCXA
IkarusTrojan-Downloader.Win32.Small
FortinetW32/Socks.HF!worm
AVGWin32:Socks-F [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:Socks-F [Wrm]?

Win32:Socks-F [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment