Worm

Worm.Generic.392786 removal instruction

Malware Removal

The Worm.Generic.392786 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Generic.392786 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Catalan
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Generic.392786?


File Info:

name: A6261BE9843073B81BBA.mlw
path: /opt/CAPEv2/storage/binaries/e12149bf12450eed36526dd7bc8ccfc1ef5f714e58893cbcbda7d31cca2a69c7
crc32: 435D853D
md5: a6261be9843073b81bba51f91b04daec
sha1: 702fbdaa3af529c8681f3247d3d84a903874253a
sha256: e12149bf12450eed36526dd7bc8ccfc1ef5f714e58893cbcbda7d31cca2a69c7
sha512: 49982a061358686077ad39eef39e325be40753cf31c2377f311fb0022de24ea1b972ed62ec588a57d99e298b65ab56e54924a2a9ca3dd6a93c16d43b9efc3e6b
ssdeep: 6144:atkEoAM4iYQqA4R6oimghRYiFncqJ6fu0nDCDyg:q8oimghCNqJF0mDyg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B347C4BF3B98A33E20538B125586BFCA6F6DC3DFA6F005FE348B51B24345855D24A92
sha3_384: b5345d703dd36884f8a99b0ffcaad64db962749a61366c51b1c860fbe1c7cd7d7ee3a1136737471c1cf9953dbccdafbd
ep_bytes: 5383ec44b823104000b9000000008a18
timestamp: 2007-10-29 06:17:05

Version Info:

0: [No Data]

Worm.Generic.392786 also known as:

BkavW32.Pharoh.Worm
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Tazebama.45
MicroWorld-eScanWorm.Generic.392786
FireEyeGeneric.mg.a6261be9843073b8
CAT-QuickHealW32.Mabezat.Dr
ALYacWorm.Generic.392786
CylanceUnsafe
VIPREWorm.Win32.Mabezat.b (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 000ad08b1 )
K7GWVirus ( 000ad08b1 )
Cybereasonmalicious.984307
BitDefenderThetaAI:FileInfector.72161D3514
CyrenW32/Mabezat.FRWO-1177
SymantecW32.Mabezat.B
ESET-NOD32Win32/Mabezat.A
TrendMicro-HouseCallPE_MABEZAT.B-O
ClamAVWin.Trojan.Mabezat-1
KasperskyWorm.Win32.Mabezat.b
BitDefenderWorm.Generic.392786
NANO-AntivirusVirus.Win32.Mabezat.kfroy
SUPERAntiSpywareTrojan.Agent/Gen-Mabezat
AvastWin32:Crypt-KUG [Trj]
RisingWorm.Mabezat!1.995D (CLASSIC)
Ad-AwareWorm.Generic.392786
SophosML/PE-A + W32/Mabezat-B
ComodoWorm.Win32.Mabezat.b@14k3c8
BaiduWin32.Worm.Mabezat.b
ZillyaWorm.MabezatGen.Win32.3
TrendMicroPE_MABEZAT.B-O
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
SentinelOneStatic AI – Suspicious PE
EmsisoftWorm.Generic.392786 (B)
IkarusWorm.Win32.Mabezat
GDataWorm.Generic.392786
JiangminTrojan/Mabezat.g
AviraWORM/Mabezat.b
Antiy-AVLTrojan/Generic.ASVirus.28
KingsoftHeur.SSC.836750.1216.(kcloud)
ViRobotWorm.Win32.Mabezat.154751
MicrosoftVirus:Win32/Mabezat.B
CynetMalicious (score: 100)
AhnLab-V3Win32/Mabezat
Acronissuspicious
McAfeeW32/Mabezat
TACHYONWorm/W32.Mabezat
VBA32Trojan.Win32.Mabezat.a
MalwarebytesWorm.Mabezat
APEXMalicious
TencentTrojan.Win32.Mabezat.a
YandexTrojan.GenAsa!0z4t/44RHDE
MAXmalware (ai score=80)
MaxSecureVirus.Mabezat.B
FortinetW32/Mabezat.B!worm
AVGWin32:Crypt-KUG [Trj]
PandaW32/Mabezat.C.worm
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Worm.Generic.392786?

Worm.Generic.392786 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment