Worm

Worm.Generic.468733 information

Malware Removal

The Worm.Generic.468733 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Generic.468733 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine Worm.Generic.468733?


File Info:

name: 6AD0E3FC5A25F54EC6F2.mlw
path: /opt/CAPEv2/storage/binaries/3c5dcac2ebf5e0608e694893c57825c0de3d8a727e81d834e2d556defd39bbf7
crc32: 11D6ACC0
md5: 6ad0e3fc5a25f54ec6f293930d929eed
sha1: cc0d6f636fcefc119148c57ac10b9f03ac60ab19
sha256: 3c5dcac2ebf5e0608e694893c57825c0de3d8a727e81d834e2d556defd39bbf7
sha512: 2740f9405c1b50710eeee90c9fe0d6d068be5341fe2c3397c35e6c46850b53c49c976ea425d12107593ae7dd189953cdc021a805481783cfd1481e20dd7490a2
ssdeep: 24576:EUvJjb55QVDSy49UW75fldM5yeUW3iufCNSH8OP/TgUO/aopcFasaOAfxu7VsL:EUvJ/XQxSt9R7xldHVuiufM+8OP/TgTp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB752356B3A18AB9F4374B311C566033E779FE262329E512B36C2C5D6F00805697BBE3
sha3_384: 7374a1a4b9fb30423ad17f18b994add2c3db19890385748a606050f236ad97052b73974f6c459200a6fe0477c8698940
ep_bytes: 558bec83c4c053565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: DA Utility Setup
FileVersion: 0.0.0.0
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Worm.Generic.468733 also known as:

DrWebProgram.RemoteAdmin
MicroWorld-eScanWorm.Generic.468733
FireEyeWorm.Generic.468733
ALYacWorm.Generic.468733
CylanceUnsafe
SangforRiskware.Win32.WinVNC-based.c
AlibabaRiskWare:Win32/WinVNC.b4b6894a
Cybereasonmalicious.c5a25f
Paloaltogeneric.ml
Kasperskynot-a-virus:RemoteAdmin.Win32.WinVNC.ahc
BitDefenderWorm.Generic.468733
NANO-AntivirusRiskware.Win32.RemoteAdmin.bryvt
AvastWin32:Malware-gen
RisingWorm.Win32.Autorun.jax (CLASSIC)
SophosGeneric PUA MM (PUA)
ComodoMalware@#33lfdtrbv2iwf
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
EmsisoftWorm.Generic.468733 (B)
GDataWorm.Generic.468733
JiangminRemoteAdmin.WinVNC.ni
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.58F88
KingsoftWin32.Troj.WinVNC-based.c.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!6AD0E3FC5A25
VBA32BScope.TrojanPSW.Banker
eGambitUnsafe.AI_Score_100%
AVGWin32:Malware-gen

How to remove Worm.Generic.468733?

Worm.Generic.468733 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment