Worm

About “Worm.Zomon.1” infection

Malware Removal

The Worm.Zomon.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Zomon.1 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing

How to determine Worm.Zomon.1?


File Info:

name: A5E2E0EE59330D69CDE2.mlw
path: /opt/CAPEv2/storage/binaries/7e47cfb214c5a589d756d7c4e3b0c0d215d65a1407b34e5fd553303dec50c482
crc32: BD73508A
md5: a5e2e0ee59330d69cde2b2141d5cf1d8
sha1: ddbd58f4f1866c0febbde3ad8ab3d534508de4b2
sha256: 7e47cfb214c5a589d756d7c4e3b0c0d215d65a1407b34e5fd553303dec50c482
sha512: 3785dabb907b7c52f334eef664bfaf3d9153b3943e82544f69c2de067480b7b7831c43a422a8c1757d3ea00fea3783b5b34dfd0c0731563f78e6d1d14644d092
ssdeep: 49152:08mWi+0QHi2TXYr04bwdapfCstl3X+gUJZDfFaZVULUXnAHXU:g2Hgpq0l3X+gqZDMULUXQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FAF6221A9C5019AAC8D38971779F47ACB8256B395631C442F2923F5CA734BCDBEC2327
sha3_384: f3e3d82ff0915835bc9734e1ddd5fb34ce4c9abfb21b4325ed1b0b64bd54659f1440df6586ad7318c020fd0cf51016b3
ep_bytes: 6a186838825b00e8c50e0000bf940000
timestamp: 2006-09-04 19:00:43

Version Info:

CompanyName: Microsoft
FileDescription: Windows
FileVersion: 1
InternalName: Windows
LegalCopyright: Copyright Microsoft
OriginalFilename: windows.exe
ProductName: Windows
ProductVersion: 1
Translation: 0x0809 0x04b0

Worm.Zomon.1 also known as:

MicroWorld-eScanGen:Worm.Zomon.1
ALYacGen:Worm.Zomon.1
CylanceUnsafe
SangforARMADILLO17
K7AntiVirusTrojan ( 0040f0cc1 )
K7GWTrojan ( 0040f0cc1 )
Cybereasonmalicious.e59330
CyrenW32/S-cfaa762b!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ANRN
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Worm.Zomon.1
AvastWin32:Kryptik-KPR [Trj]
Ad-AwareGen:Worm.Zomon.1
EmsisoftGen:Worm.Zomon.1 (B)
ComodoTrojWare.Win32.Injector.YYX@4v0tff
McAfee-GW-EditionBehavesLike.Win32.BadFile.wz
FireEyeGeneric.mg.a5e2e0ee59330d69
SophosML/PE-A + Mal/Zbot-UL
IkarusTrojan.SuspectCRC
GDataGen:Worm.Zomon.1
WebrootW32.Suspicious.Heur
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=84)
ArcabitGen:Worm.Zomon.1
CynetMalicious (score: 99)
AhnLab-V3Dropper/Win32.Injector.R41885
Acronissuspicious
McAfeeArtemis!A5E2E0EE5933
MalwarebytesTrojan.VBCrypt
RisingTrojan.Generic@AI.100 (RDML:Z8Wd4bnE8zX59CWg31PPLA)
YandexTrojan.Agent!NFn773RVjo4
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.YYX!tr
BitDefenderThetaGen:NN.ZexaF.34712.@t3@aKZlHBoi
AVGWin32:Kryptik-KPR [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.Zomon.1?

Worm.Zomon.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment