Worm

Worm.Generic.11023 malicious file

Malware Removal

The Worm.Generic.11023 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Generic.11023 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Worm.Generic.11023?


File Info:

name: 83F9EE8957E1B2A9042D.mlw
path: /opt/CAPEv2/storage/binaries/cd3390918e8e4a6a30506dbd4e6d7ec0df3c21b9882e625f47b8a84df362d02d
crc32: A610DF78
md5: 83f9ee8957e1b2a9042dfa21c46dab38
sha1: c94acc4b43afb118611933b5ec7e82cd94e50a61
sha256: cd3390918e8e4a6a30506dbd4e6d7ec0df3c21b9882e625f47b8a84df362d02d
sha512: 238bee3e17b54df61f0e2e881b4fec556d21a30844aab3a056effa9996cdeb7daaf9e10293c29401ee1fb05a87eec19cc154e2a95c3e0b05e081b163c1e3e6ee
ssdeep: 384:/TU+dvdGzgztVA0lCgZ7AyBX08UKLwztV:/zv75VA0l9JlBUKLw5V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10284FF1E2184D961E6E85E344B9374992A0E6EDEF102CD727C973F79FA2A3903601D1F
sha3_384: a6026ad9abba676c56ae098c4a2cf9dfc1b3d1883c56b4e03b70e74f018fa9fd75eabf573371f0539114ff9e5ddf36bb
ep_bytes: 68bcb54500e8f0ffffff000000000000
timestamp: 2007-05-27 11:35:08

Version Info:

Translation: 0x0409 0x04b0
Comments: Brand
CompanyName: Tkschool
ProductName: Brand BoOmsUng
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ntsvc
OriginalFilename: ntsvc.exe

Worm.Generic.11023 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanWorm.Generic.11023
FireEyeWorm.Generic.11023
McAfeeW32/Autorun.worm.ie
CylanceUnsafe
BitDefenderWorm.Generic.11023
ESET-NOD32Win32/VB.NKS
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Autorun.7d31c02a
NANO-AntivirusTrojan.Win32.VB.edmdsl
RisingTrojan.VB!8.B20 (CLOUD)
Ad-AwareWorm.Generic.11023
EmsisoftWorm.Generic.11023 (B)
McAfee-GW-EditionW32/Autorun.worm.ie
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.VB
AviraTR/VB.Agent.aybp
MAXmalware (ai score=89)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWorm.Generic.11023
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZevbaCO.34742.ym0@aSaKkPai
PandaTrj/CI.A
TencentWin32.Trojan.Vb.Eckn
SentinelOneStatic AI – Malicious PE
FortinetW32/VB.NKS!tr
AVGWin32:Malware-gen
Cybereasonmalicious.957e1b
AvastWin32:Malware-gen

How to remove Worm.Generic.11023?

Worm.Generic.11023 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment