Worm

Worm.Generic.439408 removal

Malware Removal

The Worm.Generic.439408 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Generic.439408 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools

How to determine Worm.Generic.439408?


File Info:

name: 688847EA105733F9008A.mlw
path: /opt/CAPEv2/storage/binaries/007e2025b4011b99de120cd75d6460c65a1e4f959df17e9edfbbda1217eebf8b
crc32: 19F714C0
md5: 688847ea105733f9008a0ea25fbdab4c
sha1: 9951dfa5832625d82a7e448616b766bd797f0a17
sha256: 007e2025b4011b99de120cd75d6460c65a1e4f959df17e9edfbbda1217eebf8b
sha512: 0e63473dc5ed58f62ae4a72926cb28a014085e31ce1616af7dee96fdb359721265cc346cbb3f4bade3129d66f8efd32c423f6ce980b2df3f9542f5b9f00bc7bc
ssdeep: 3072:1pWz8+SqJ38EJkTdVxIKSF1TewlQy5KqnYxriy:1pWjrp2dVx81TTmy8qnYOy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9E38B5ECB7360F2FBE3FEF844257315856BAE90086B504A70D928FB59BEA8C45442CD
sha3_384: 365fa6301fbf8108d1e3fa7b0c3c024f1bc983dc4f9aa921381616f4c5bd3ff7200915b03ea9889bf80ccbbb831c5784
ep_bytes: 558bec83c4f0b81c784000e828b6ffff
timestamp: 2012-12-15 02:34:53

Version Info:

InternalName: avscan
ProductName: AntiVir Desktop
CompanyName: Avira GmbH
LegalCopyright: Copyright © 2000 - 2010 Avira GmbH. All rights reserved.
ProductVersion: 10.03.00.07
FileDescription: On-Demand Scanner
LegalTrademarks: AntiVir® is a registered trademark of Avira GmbH, Germany.
FileVersion: 10.03.00.07
OriginalFilename: avscan.exe
Translation: 0x0409 0x04b0

Worm.Generic.439408 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanWorm.Generic.439408
ClamAVWin.Worm.Agent-1145537
FireEyeGeneric.mg.688847ea105733f9
CylanceUnsafe
VIPREWorm.Generic.439408
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Dorkbot.bdaf5432
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
VirITTrojan.Win32.Generic.BKWM
CyrenW32/A-60d79c3d!Eldorado
SymantecW32.IRCBot.NG
Elasticmalicious (high confidence)
ESET-NOD32Win32/Dorkbot.B
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderWorm.Generic.439408
NANO-AntivirusTrojan.Win32.Zbot.hcfub
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b3e3d1
Ad-AwareWorm.Generic.439408
EmsisoftWorm.Generic.439408 (B)
ComodoTrojWare.Win32.Kryptik.YDL@4m44uy
DrWebTrojan.PWS.Panda.547
ZillyaTrojan.Jorik.Win32.177535
TrendMicroTROJ_GEN.R002C0DFR22
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWorm.Generic.439408
AviraDR/Delphi.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.43F
KingsoftWin32.HeurC.KVM011.a.(kcloud)
ViRobotBackdoor.Win32.U.Ruskill.150016
MicrosoftWorm:Win32/Dorkbot.A
GoogleDetected
AhnLab-V3Backdoor/Win32.Ruskill.R55571
BitDefenderThetaGen:NN.ZelphiF.34592.jO0@ae9rKaiG
ALYacWorm.Generic.439408
MAXmalware (ai score=80)
VBA32TrojanPSW.Panda
MalwarebytesWorm.DorkBot
TrendMicro-HouseCallTROJ_GEN.R002C0DFR22
RisingTrojan.Generic@AI.88 (RDML:yLI8NW3YkhddHvoR02qaFQ)
YandexTrojan.GenAsa!6TXMv77i1UE
IkarusVirus.Win32.Heur
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.AC.238038!tr
AVGWin32:Malware-gen
Cybereasonmalicious.a10573
PandaTrj/CI.A

How to remove Worm.Generic.439408?

Worm.Generic.439408 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment