Worm

Win32:WormX-gen [Wrm] (file analysis)

Malware Removal

The Win32:WormX-gen [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:WormX-gen [Wrm] virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Sniffs keystrokes
  • A potential decoy document was displayed to the user
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

wxanalytics.ru

How to determine Win32:WormX-gen [Wrm]?


File Info:

crc32: 7DBE0022
md5: 68ad1df4853cb944dfbeaa741db2ac43
name: __________________-____-______________________-________________-__________-__-______
sha1: 93052ad522a75b4ed5428013d1ea0a08cb77d75e
sha256: 0d3a942d2e9d93a9bdecb8ea80afc1e52cbd0c90bf6eb5e6f8d02dc44648a1e6
sha512: 5e8c115d8e9234beb1249b2b126dfc22ab08065daa4d7fb067f81215b777268dba40cd738636d4bb106f9b532615cb289a94a96bd33abf5c1158edf46503036e
ssdeep: 49152:KYrC8UsGuTwPpFvVfCHdeQKyZURQ1EjTq:A8UsqFvVfC9eQKyZURQ1EjT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32:WormX-gen [Wrm] also known as:

BkavW32.AIDetectVM.malware2
DrWebWin32.HLLW.Rendoc.3
MicroWorld-eScanGen:Heur.Mint.Zard.36
CAT-QuickHealWorm.Fadok.A5
McAfeeGenericRXAH-AG!68AD1DF4853C
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Heur.Mint.Zard.36
K7GWTrojan ( 004c3bbe1 )
K7AntiVirusTrojan ( 004c3bbe1 )
TrendMicroWORM_FAKEDOC_FD050240.UVPM
BitDefenderThetaGen:NN.ZexaF.34104.7vW@aCA4kqnk
F-ProtW32/FakeDoc.F.gen!Eldorado
APEXMalicious
AvastWin32:WormX-gen [Wrm]
ClamAVWin.Malware.Razy-6723913-0
GDataGen:Heur.Mint.Zard.36
KasperskyTrojan.Win32.Agent.ifdx
NANO-AntivirusTrojan.Win32.Rendoc.faojir
TencentMalware.Win32.Gencirc.10b6abd3
Ad-AwareGen:Heur.Mint.Zard.36
EmsisoftWorm.FakeDoc (A)
ComodoTrojWare.Win32.Scar.FAKD@5xdxi2
F-SecureTrojan.TR/ATRAPS.Gen4
BaiduWin32.Worm.FakeDoc.a
ZillyaTrojan.Scar.Win32.88546
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.68ad1df4853cb944
SophosTroj/FakeDoc-B
IkarusWorm.Win32.Fakedoc
CyrenW32/FakeDoc.F.gen!Eldorado
JiangminWorm.Agent.ju
MaxSecureTrojan.Agent.ifdx
AviraTR/ATRAPS.Gen4
Antiy-AVLTrojan/Win32.Scar.jfya
Endgamemalicious (high confidence)
ArcabitTrojan.Mint.Zard.36
SUPERAntiSpywareTrojan.Agent/Gen-FakeDoc
ZoneAlarmTrojan.Win32.Agent.ifdx
MicrosoftWorm:Win32/Fadok!rfn
AhnLab-V3Worm/Win32.Fadok.R189010
Acronissuspicious
VBA32Trojan.Agent
ALYacGen:Heur.Mint.Zard.36
MAXmalware (ai score=88)
MalwarebytesTrojan.FakeDoc
PandaTrj/Genetic.gen
ZonerTrojan.Win32.61633
ESET-NOD32Win32/FakeDoc.A
TrendMicro-HouseCallWORM_FAKEDOC_FD050240.UVPM
RisingWorm.Fadok!1.A753 (TFE:dGZlOgV/PitkFSzGcA)
YandexTrojan.DownLoader!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/FakeDoc.A!worm
AVGWin32:WormX-gen [Wrm]
Qihoo-360QVM41.1.Malware.Gen

How to remove Win32:WormX-gen [Wrm]?

Win32:WormX-gen [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment