Worm

Worm.FolStart information

Malware Removal

The Worm.FolStart is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.FolStart virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Worm.FolStart?


File Info:

name: 8E540F51CD16BE076561.mlw
path: /opt/CAPEv2/storage/binaries/00352449dbe9bc0edde9727785c2f9da6f6b6aa399b6901a42f71be902e7e7eb
crc32: C14E1E5F
md5: 8e540f51cd16be0765613587fa767497
sha1: 168a85b2a219795462eddd98a0ca8ace4b78fcbd
sha256: 00352449dbe9bc0edde9727785c2f9da6f6b6aa399b6901a42f71be902e7e7eb
sha512: 28172b71056907e84b9854dd18ef54089135f63265d7da4dbac602d40ce61f69a9e289452ea8492a669fb71df3fe521f901aeef0e179fa590753bcf300e80926
ssdeep: 1536:i3QD+SfH2miO6TIjnM5Y1SFOCz1CgT5sszU8yX2QhkkZa:OGfWdGjnMIsPz1/ysQxX26kI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126346A1377E2C8F6E17609314FAA5BB597B6FD308D359A1B1320772E1C319828D2A763
sha3_384: f01c9f73932ce0038b2b2221d2393aaa739ffaa08f0e59410e4f15f699b2f8fac7992315110e483bd262701e7515ed13
ep_bytes: 5589e56aff68f8234100687877400064
timestamp: 2055-05-25 18:10:40

Version Info:

CompanyName:
FileDescription: Normal Directory MFC Application
FileVersion: 1, 0, 0, 1
InternalName: Normal Directory
LegalCopyright: Copyright (C) 2009
LegalTrademarks:
OriginalFilename: Normal Directory.EXE
ProductName: Normal Directory Application
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Worm.FolStart also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner.18119
MicroWorld-eScanTrojan.Agent.GEWD
ClamAVWin.Trojan.Virut-30
CAT-QuickHealW32.Virut.D
MalwarebytesMalware.AI.3578973977
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 00345a5b1 )
K7GWTrojan ( 00345a5b1 )
Cybereasonmalicious.1cd16b
BitDefenderThetaGen:NN.ZexaF.36250.py0@aqJROtkj
VirITWin32.Cheburgen.A
CyrenW32/Agent.CAA.gen!Eldorado
SymantecW32.Rotinom
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.NOM
ZonerTrojan.Win32.36734
APEXMalicious
CynetMalicious (score: 70)
KasperskyHEUR:Worm.Win32.FolStart.pef
BitDefenderTrojan.Agent.GEWD
SUPERAntiSpywareTrojan.Agent/Gen-Autorun
AvastWin32:Agent-ANIM [Trj]
TencentWorm.Win32.AutoRun.h
TACHYONTrojan/W32.Agent.249856.AQL
EmsisoftTrojan.Agent.GEWD (B)
F-SecureHeuristic.HEUR/Patched.Ren
BaiduWin32.Worm.Agent.fc
VIPRETrojan.Agent.GEWD
TrendMicroWorm.Win32.FOLDRUN.SMA
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8e540f51cd16be07
SophosMal/Behav-043
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.19L4SV3
AviraHEUR/Patched.Ren
Antiy-AVLTrojan/Win32.Agent
XcitiumWorm.Win32.Agent.NEC0@1lq821
ArcabitTrojan.Agent.GEWD
ZoneAlarmHEUR:Worm.Win32.FolStart.pef
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
Acronissuspicious
VBA32Worm.FolStart
ALYacTrojan.Agent.GEWD
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWorm.Win32.FOLDRUN.SMA
RisingWorm.Autorun!1.DD90 (CLASSIC)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Wacatac.B!tr
AVGWin32:Agent-ANIM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Worm.FolStart?

Worm.FolStart removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment