Worm

Worm:Win32/Fesber.A removal tips

Malware Removal

The Worm:Win32/Fesber.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Fesber.A virus can do?

  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Attempts to connect to a dead IP:Port (202 unique times)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Worm:Win32/Fesber.A?


File Info:

name: 2F095B4C39D25CED5EBB.mlw
path: /opt/CAPEv2/storage/binaries/118b81eed20b7b07d98dd13d1ce8af868223258a30ec4c8fbfbfce6baa16fac8
crc32: 407391F2
md5: 2f095b4c39d25ced5ebbe77601ca8499
sha1: 4b8f0593a271e520d915603cb759a2c5b5c9a16d
sha256: 118b81eed20b7b07d98dd13d1ce8af868223258a30ec4c8fbfbfce6baa16fac8
sha512: 140c6c14a6bea9887cdc02929ef0b455c2e8e5b1c6581783f7fe76b81486effb76687187911094b5779a030201b4a96289e8f793122d99283afe5bf657ccc1f1
ssdeep: 12288:I28PZT3YZ9okuA9oBSrnAfCp2kodolCKu1c:jJZua9ob7ko+lCKu1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FAB46B1EF7AC54F5D026917C8996C24AF6B2B8301F5196CB2260833E7F37AE45E39B11
sha3_384: abd4b94e08174843dbbd44ceb827d21dddb5bac1154895ceacc3f1c93c11a8d6d4c5d4c4d1b31cbb4c2de979064b34d0
ep_bytes: 558bec83c4ec33c08945ecb8208c4000
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Fesber.A also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Wabot.lh0Z
Elasticmalicious (high confidence)
DrWebWin32.HLLW.FSB
MicroWorld-eScanDropped:Trojan.GenericKD.31231822
FireEyeGeneric.mg.2f095b4c39d25ced
McAfeeW32/Keco.worm.gen
CylanceUnsafe
ZillyaBackdoor.Delf.Win32.19961
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaBackdoor:Win32/LunaStorm.584eee3c
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.c39d25
BitDefenderThetaAI:Packer.128895A320
CyrenW32/Delfloader.B.gen!Eldorado
SymantecW32.HLLP.Yero.Worm.dr
ESET-NOD32a variant of Win32/LunaStorm.D
TrendMicro-HouseCallWORM_YERO.A
Paloaltogeneric.ml
ClamAVWin.Worm.Fesber-9939367-0
KasperskyBackdoor.Win32.Delf.lz
BitDefenderDropped:Trojan.GenericKD.31231822
NANO-AntivirusTrojan.Win32.Fesber.fjhfvl
AvastWin32:Agent-AVCC [Trj]
TencentMalware.Win32.Gencirc.10d0197b
Ad-AwareDropped:Trojan.GenericKD.31231822
EmsisoftDropped:Trojan.GenericKD.31231822 (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
BaiduWin32.Trojan-Dropper.Agent.ad
TrendMicroWORM_YERO.A
McAfee-GW-EditionBehavesLike.Win32.HLLP.hm
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Delf.bwp
MaxSecureTrojan.Malware.1943155.susgen
AviraWORM/Fesber
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.Fesber.g
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftWorm:Win32/Fesber.A
ZoneAlarmBackdoor.Win32.Delf.lz
GDataDropped:Trojan.GenericKD.31231822
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C35566
Acronissuspicious
VBA32BScope.Backdoor.Agent
ALYacDropped:Trojan.GenericKD.31231822
MalwarebytesMalware.AI.3569880061
APEXMalicious
RisingWorm.Win32.Fesber.e (CLOUD)
YandexTrojan.GenAsa!rbAcHlWfCJ4
eGambitGeneric.Malware
FortinetW32/Delf.NRF!tr
AVGWin32:Agent-AVCC [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Fesber.A?

Worm:Win32/Fesber.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment