Worm

How to remove “Worm.DarkSnow.A.mue”?

Malware Removal

The Worm.DarkSnow.A.mue is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.DarkSnow.A.mue virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm.DarkSnow.A.mue?


File Info:

name: 2B87FAB30549FDA9688F.mlw
path: /opt/CAPEv2/storage/binaries/0040e7b12bded6fecb763a1b79dee3c624bfd49d65d8d71cb84ffb73812bdcd2
crc32: 944D2A5B
md5: 2b87fab30549fda9688f4b68a28b6764
sha1: 600e9f2822b53214683a9e4941895edf88df38ca
sha256: 0040e7b12bded6fecb763a1b79dee3c624bfd49d65d8d71cb84ffb73812bdcd2
sha512: 4b63597bda0d6c9513c9466fc03e78f9e92e92b6a3ae79659b163edfae4fa40e490a6a8c398186e699324a725f9b356dffe89f4d9714fed6f082b4ed6f319a56
ssdeep: 3072:kOZ45tL9rcZ8y27OXzGleAERFZWcy+ZYm6eRCxRshG+jmjrmFaCVMjBEEn+HY/LZ:kOZYtLJciOVA21go4GkCqE9Y/LCq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10D249E207B81C0B7D5B3017008F85B7A65BDBD62477055C7B3D82B1F1A306D2AB7AAA7
sha3_384: 09d67053a5c080d6db23dadbcd9b0dd512756243b649f4cfe95f1b49663639e8d19bf5070eefbcbfca2fea24115e0be9
ep_bytes: e8bf5c0000e97bfeffff558bec8b4514
timestamp: 2015-01-29 17:47:49

Version Info:

CompanyName: Microsoft Corporation
FileDescription: 微软设备健康助手服务
FileVersion: 1.5.3.1
InternalName: DhMachineSvc.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: DhMachineSvc.exe
ProductName: 微软设备健康助手
ProductVersion: 1.5.3.1
Translation: 0x0804 0x04b0

Worm.DarkSnow.A.mue also known as:

LionicWorm.Win32.WhiteIce.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.WhiteIce.Dam
FireEyeWin32.WhiteIce.Dam
CAT-QuickHealWorm.DarkSnow.A.mue
McAfeeArtemis!2B87FAB30549
CylanceUnsafe
SangforAdware.Win32.WhiteIce.Dam
K7AntiVirusTrojan ( 0040b0d91 )
K7GWTrojan ( 0040b0d91 )
Cybereasonmalicious.30549f
BitDefenderThetaAI:FileInfector.F4766A9612
VirITWin32.Tufik.E
CyrenW32/FakeFolder.P.gen!Eldorado
SymantecTrojan.Gen
ESET-NOD32Win32/Whiteice.A
BaiduWin32.Worm.WhiteIce.a
TrendMicro-HouseCallPE_DARKSNOW.A-O
Paloaltogeneric.ml
ClamAVWin.Worm.Whiteice-4
KasperskyWorm.Win32.WhiteIce.a
BitDefenderWin32.WhiteIce.Dam
NANO-AntivirusTrojan.Win32.PEPM.fhnbzh
AvastWin32:Malware-gen
TencentTrojan.Win32.Genome.aad
Ad-AwareWin32.WhiteIce.Dam
EmsisoftWin32.WhiteIce.Dam (B)
DrWebWorm.Siggen.12153
TrendMicroPE_DARKSNOW.A-O
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
APEXMalicious
GDataWin32.WhiteIce.Dam
AviraWORM/Rbot.Gen
MAXmalware (ai score=83)
KingsoftWin32.Heur.KVM003.a.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
VBA32Trojan.Wacatac
ALYacWin32.WhiteIce.Dam
MalwarebytesWorm.WhiteIce
IkarusVirus.Win32.Whiteice
RisingTrojan.Win32.Generic.190B40CA (C64:YzY0Ol3CaHPs2oVs)
MaxSecureTrojan.Malware.172598.susgen
FortinetW32/Whiteice.A
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Worm.DarkSnow.A.mue?

Worm.DarkSnow.A.mue removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment