Worm

Worm.Win32.Socks.pgi malicious file

Malware Removal

The Worm.Win32.Socks.pgi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Socks.pgi virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm.Win32.Socks.pgi?


File Info:

name: 11644B8A4AC39070E231.mlw
path: /opt/CAPEv2/storage/binaries/816e06ed0a017ca57b153152395a51d52780c1c64d805d0e415b323a6907a9fb
crc32: BDC1F20C
md5: 11644b8a4ac39070e23143813f7efdaf
sha1: 8a4df08e9aca27bd8135a88d403b1352140baf33
sha256: 816e06ed0a017ca57b153152395a51d52780c1c64d805d0e415b323a6907a9fb
sha512: 3356d3f33607af421744a2093117c8696361fe1c1ec9c0b66f0aeaf969eef28430ee5954a4890efe7cbc994ab3144406a2bd6088efc6ac916b69043f878c6924
ssdeep: 6144:P4efY7KbmzK/DasbS7/B+ybSxbSxbSxbS7/B+ybS6GAm/SQOmibSj:AefJeK/DaOqZeeeqZP9vu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D44021A6342F930EDE30EF61F493854EC7E77409AD6A6B08110D7EB1C2BEC6E5245AD
sha3_384: d87b535816856503951ef250cc20db8822b07d82ee7433fbb6f7abef8b13fb6f704fa2c47aaeedcf66a6a048a24552b4
ep_bytes: 558bec6aff688888400068a0a6400064
timestamp: 2008-04-02 11:34:39

Version Info:

0: [No Data]

Worm.Win32.Socks.pgi also known as:

BkavW32.FamVT.SockTTc.Worm
LionicWorm.Win32.Socks.lBMT
MicroWorld-eScanTrojan.Crypt.EJ
ClamAVWin.Worm.Socks-5
FireEyeGeneric.mg.11644b8a4ac39070
CAT-QuickHealWorm.Socks.13494
McAfeeBackDoor-DOQ
Cylanceunsafe
ZillyaWorm.Socks.Win32.9
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 00033eea1 )
AlibabaWorm:Win32/Socks.d23cf7b4
K7GWTrojan-Downloader ( 00033eea1 )
Cybereasonmalicious.a4ac39
BaiduWin32.Trojan-PSW.Agent.b
CyrenW32/Socks.A.gen!Eldorado
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Socks.NAJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Socks.pgi
BitDefenderTrojan.Crypt.EJ
NANO-AntivirusTrojan.Win32.Socks.oovk
SUPERAntiSpywareWorm.Socks
AvastWin32:Socks-H [Wrm]
TencentMalware.Win32.Gencirc.10b2cf43
SophosTroj/Scrub-Gen
F-SecureTrojan.TR/Dldr.Agent.agl
DrWebTrojan.DownLoader.56336
VIPRETrojan.Crypt.EJ
TrendMicroWORM_SOCKS.BL
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Crypt.EJ (B)
IkarusTrojan-Downloader.Win32.Small
GDataWin32.Trojan.PSE.19URAP5
JiangminWorm/Socks.k
AviraTR/Dldr.Agent.agl
Antiy-AVLWorm/Win32.Socks
XcitiumTrojWare.Win32.TrojanDownloader.Agent.~ZAAG@2vmtm
ArcabitTrojan.Crypt.EJ
ZoneAlarmWorm.Win32.Socks.pgi
MicrosoftBackdoor:Win32/Koceg.gen!A
GoogleDetected
AhnLab-V3Worm/Win32.Socks.R2364
BitDefenderThetaAI:Packer.299B72B31B
ALYacTrojan.Crypt.EJ
MAXmalware (ai score=87)
VBA32SScope.Worm.Socks.afv
MalwarebytesSock.Backdoor.Bot.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_SOCKS.BL
RisingWorm.Socks!1.C134 (CLASSIC)
YandexWorm.Socks!xDmQwZegYvM
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Socks
FortinetW32/Socks.HF!worm
AVGWin32:Socks-H [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.Win32.Socks.pgi?

Worm.Win32.Socks.pgi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment