Categories: Worm

What is “Worm.Win32.Pajetbin.pef”?

The Worm.Win32.Pajetbin.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Pajetbin.pef virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm.Win32.Pajetbin.pef?


File Info:

name: 6EF8F857B5FBDC6E08BB.mlwpath: /opt/CAPEv2/storage/binaries/d23da211302d36d318c0522e9fa5bc1b1f63edb32b5e61790bbda2706dd37615crc32: D7D0F1FCmd5: 6ef8f857b5fbdc6e08bb39106a2ed4b8sha1: 87348bf45d040b4899b0bcb30a6bef188bd98e08sha256: d23da211302d36d318c0522e9fa5bc1b1f63edb32b5e61790bbda2706dd37615sha512: 98069d02a1c9d453f51c25dceb9a4602f130a9eb090fbb1c85de9e80c1c0b1159404a88a59b21214d7613bb3bc558e4dd61664bf8b209545709a4e3a481e5c3assdeep: 12288:9gsHyMqLHFZlxMAwSfxL/2Dc3jDLLmt0LDQewsAjRdDMlkss8WBTGv5vnBNUbTYI:9FHDUTxaewsAjXss86TYvLfUTtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T1F5756C2EFE64DDB5C66B09348661C32D93357C200B1196C7B3A8B64EDD32FD12D3AA16sha3_384: 1061614f54273c5e3e0f74ae9d6799e49c809b6f55578748ddba585694432b0f70bab28f1c3e9e764946974cbaabf110ep_bytes: e8ca560000e941feffff3b0dcc054200timestamp: 2008-07-02 15:50:28

Version Info:

Comments: LegalCopyright: License: MPL 1.1/GPL 2.0/LGPL 2.1CompanyName: Mozilla FoundationFileDescription: Firefox Software UpdaterFileVersion: 1.9.0.1ProductVersion: 1.9.0.1InternalName: LegalTrademarks: MozillaOriginalFilename: updater.exeProductName: FirefoxBuildID: 2008070207Translation: 0x0000 0x04b0

Worm.Win32.Pajetbin.pef also known as:

Bkav W32.AIDetect.malware1
tehtris Generic.Malware
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Cybereason malicious.45d040
Cyren W32/Emotet.BBS.gen!Eldorado
Symantec ML.Attribute.HighConfidence
APEX Malicious
ClamAV Win.Malware.Midie-9866099-0
Kaspersky HEUR:Worm.Win32.Pajetbin.pef
Sophos Generic ML PUA (PUA)
McAfee-GW-Edition BehavesLike.Win32.BadFile.tm
FireEye Generic.mg.6ef8f857b5fbdc6e
SentinelOne Static AI – Malicious PE
GData Win32.Trojan.PSE.1OJHE4X
Jiangmin Packed.Krap.gvvy
Avira HEUR/AGEN.1222776
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
Acronis suspicious
McAfee Artemis!6EF8F857B5FB
VBA32 Trojan.Downloader
TrendMicro-HouseCall TROJ_GEN.R03BH0CDM22
Ikarus Trojan.Agent
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Emotet.212B!tr
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike win/grayware_confidence_90% (W)

How to remove Worm.Win32.Pajetbin.pef?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

About “MSIL/TrojanDownloader.Agent.QQN” infection

The MSIL/TrojanDownloader.Agent.QQN is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

Malware.AI.975225574 removal

The Malware.AI.975225574 is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

Ursu.840201 (file analysis)

The Ursu.840201 is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Should I remove “Malware.AI.4025139158”?

The Malware.AI.4025139158 is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Tedy.271097 removal instruction

The Tedy.271097 is considered dangerous by lots of security experts. When this infection is active,…

53 mins ago

Malware.AI.1637728237 removal guide

The Malware.AI.1637728237 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago