Worm

Worm:Win32/Feebs.EA.dll removal guide

Malware Removal

The Worm:Win32/Feebs.EA.dll is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Feebs.EA.dll virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself

How to determine Worm:Win32/Feebs.EA.dll?


File Info:

name: 06C8574B2ECA0FE20012.mlw
path: /opt/CAPEv2/storage/binaries/63f34fdde7459149f466cdc830fcb2b2bc87e053c90bda1db278a88468b20cc6
crc32: 0496B971
md5: 06c8574b2eca0fe2001252b7c0e6209d
sha1: 31c72bf294d53c2ed3d232dff32846f9e8040b1a
sha256: 63f34fdde7459149f466cdc830fcb2b2bc87e053c90bda1db278a88468b20cc6
sha512: 460b4c83463eef1c7908337626402e0b7c990b4c85693c9a026e2f10a93282ddacdbbd7891b1613293cbca8b3afc74178497fde4e0601f1850c847e190018dbc
ssdeep: 1536:H/YBFRRLpOLXPh9zXZ2nuVd0IV1ESHDHheQ:H/Yzz8Lfh9TSuVd71jHDB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF4302ADB07FD527DCBC0AFA678B410E11864BFE1FF8C5162FEA5181A305C99E11D688
sha3_384: c2ec2f17d9644ab5b12a1068d3496fd74ba09a8037303a140db5b63815e8db3a83933c88b11816796df6a5d7a3f2d4b9
ep_bytes: 81ec140100005355a100e74000668b0d
timestamp: 2006-04-08 17:20:48

Version Info:

0: [No Data]

Worm:Win32/Feebs.EA.dll also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.Generic.o!c
Elasticmalicious (high confidence)
ClamAVWin.Worm.Feebs-113
FireEyeGeneric.mg.06c8574b2eca0fe2
McAfeeW32/Feebs.b
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWorm.Win32.Feebs.fu
K7AntiVirusTrojan ( 0000ca9d1 )
AlibabaMalware:Win32/km_2a8b722.None
K7GWTrojan ( 0000ca9d1 )
Cybereasonmalicious.b2eca0
CyrenW32/Feebs.NUTE-1211
SymantecW32.Feebs
ESET-NOD32Win32/Mocalo.CJ
APEXMalicious
AvastWin32:Feebs-BQ [Trj]
CynetMalicious (score: 100)
KasperskyWorm.Win32.Feebs.fu
BitDefenderWin32.Worm.Feebs.1.Gen
NANO-AntivirusTrojan.Win32.Feebs.gqln
MicroWorld-eScanWin32.Worm.Feebs.1.Gen
TencentWin32.Worm.Feebs.Gvo
Ad-AwareWin32.Worm.Feebs.1.Gen
SophosMal/Generic-R
ComodoWorm.Win32.Mocalo.CJ@2rq2
DrWebWin32.HLLM.Graz.based
ZillyaWorm.Feebs.Win32.23
TrendMicroWORM_FEEBS.GEN
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.qc
EmsisoftWin32.Worm.Feebs.1.Gen (B)
Paloaltogeneric.ml
GDataWin32.Worm.Feebs.1.Gen
JiangminWorm/Feebs.ea
WebrootWorm:Win32/Feebs.CM.dll
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.F27B48
ViRobotWorm.Win32.Feebs.56322
MicrosoftWorm:Win32/Feebs.EA.dll
Acronissuspicious
BitDefenderThetaAI:FileInfector.D7736DD516
ALYacWin32.Worm.Feebs.1.Gen
MAXmalware (ai score=100)
VBA32SScope.Worm.Feebs
TrendMicro-HouseCallWORM_FEEBS.GEN
RisingWorm.Feebs.hs (CLOUD)
YandexTrojan.GenAsa!ZVR1txQHrEE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Feebs.EU!worm
AVGWin32:Feebs-BQ [Trj]
PandaW32/Feebs.DK.worm
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Feebs.EA.dll?

Worm:Win32/Feebs.EA.dll removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment