Worm

Worm:Win32/Fasong!pz information

Malware Removal

The Worm:Win32/Fasong!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Fasong!pz virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Fasong!pz?


File Info:

name: 3A49CFCFC79C391AB7DE.mlw
path: /opt/CAPEv2/storage/binaries/0e83278991c6da9303a293d357f5f1911816f30681a35120608252c1e883335f
crc32: FB82A95B
md5: 3a49cfcfc79c391ab7de092870d7ac88
sha1: 8da933e0e0a209038ed48be651c138a5b4e85aa4
sha256: 0e83278991c6da9303a293d357f5f1911816f30681a35120608252c1e883335f
sha512: d8639ef5c7aa0d831a23b778d2dd018868956c39137045a694ad3401133c1b765b493202d082c17b7b8c9b35098e9fbd6a7962c087a90edcf3462751b94b7ecf
ssdeep: 3072:cDVGX216H9+CQ+3bdGNtak/vDVGX216H9+Snf:AVDI0NZLVD
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T11204AD11B7F586A4FAF31B31993286901E37BC96ED70CB9D2654F96F1D72A858820333
sha3_384: d2cc15410c205b8b3d01fec434d68796cb9f786b7326857da45f1589ac574b30cf9f043b4af1645a2d60e02eb5eedc76
ep_bytes: 807c2408010f857d01000060be004041
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Fasong!pz also known as:

BkavW32.AIDetectMalware
DrWebTrojan.PWS.Legmir.340
MicroWorld-eScanGen:Variant.Graftor.31129
ClamAVWin.Spyware.69902-2
FireEyeGeneric.mg.3a49cfcfc79c391a
SkyhighBehavesLike.Win32.Generic.ch
McAfeePWS-LegMir.ao
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Lmir.Win32.60
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00009c9e1 )
K7GWTrojan ( 00009c9e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.084882681F
VirITTrojan.Win32.Legendmir.J
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Fasong.H
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.Lmir.pv
BitDefenderGen:Variant.Graftor.31129
NANO-AntivirusTrojan.Win32.Lmir.heog
AvastWin32:Lmir-HJ [Trj]
TencentTrojan-GameThief.Win32.Lmir.kb
EmsisoftGen:Variant.Graftor.31129 (B)
F-SecureTrojan.TR/ATRAPS.Gen
VIPREGen:Variant.Graftor.31129
TrendMicroTSPY_LMIR.TF
SophosTroj/PWS-BUY
IkarusTrojan-GameThief.Win32.Lmir
GDataWin32.Trojan.PSE.1D5X6RD
JiangminTrojan/PSW.LMir.acd.Hook
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[GameThief]/Win32.Lmir
XcitiumTrojWare.Win32.GameThief.OnLineGames.~BAAJ@1hyn7
ArcabitTrojan.Graftor.D7999
ViRobotTrojan.Win32.A.PSW-Lmir.59059[UPX]
ZoneAlarmTrojan-GameThief.Win32.Lmir.pv
MicrosoftWorm:Win32/Fasong!pz
VaristW32/Legendmir.IEJM-7480
AhnLab-V3Trojan/Win32.Lmirhack.R49486
VBA32TrojanPSW.Lmir
ALYacGen:Variant.Graftor.31129
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Legmir.gen
TrendMicro-HouseCallTSPY_LMIR.TF
RisingTrojan.PSW.LMir.and (CLASSIC)
YandexTrojan.PWS.Legendmir!YUY7JsKYO9o
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qqpass.A!tr
AVGWin32:Lmir-HJ [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Fasong!pz?

Worm:Win32/Fasong!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment