Worm

How to remove “Worm:Win32/Folstart!pz”?

Malware Removal

The Worm:Win32/Folstart!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Folstart!pz virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Worm:Win32/Folstart!pz?


File Info:

name: 4C0D65F61285397BCE4E.mlw
path: /opt/CAPEv2/storage/binaries/11980c66468a63495121aaa654e199b60687fa2bba53c1db4e8de7dfda9a3182
crc32: 553546F7
md5: 4c0d65f61285397bce4ebefcdaffba26
sha1: 6dc383509da45bd40f8205625fdd598a26ce74c7
sha256: 11980c66468a63495121aaa654e199b60687fa2bba53c1db4e8de7dfda9a3182
sha512: cccf0829261b447bc0818ac61c49ca5431b816ae7b4d5e9ea6db2190cd3cd0d476627b3496b6541df515cccf2e5e87c8002f120bd5458dd5eb1ff2523356c9dc
ssdeep: 1536:SqQD+SfHZgmiO6TIjnM5Y1SFOCz1CgT5sszU8yX2QhkkZa:vGf5gdGjnMIsPz1/ysQxX26kI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A346A1373E2C8F6E17609314FAA5BB597B6FD308D359A1B1320772E1C319829D2A763
sha3_384: 006b5b141c6ad1cd6e9289d787bf4c09220c25eda6687e8990e4421782b9f2fd4fba633a2b17c4c9f8d6dc1fea7893ae
ep_bytes: 558bec6aff68f8234100687877400064
timestamp: 2055-05-25 18:10:40

Version Info:

CompanyName:
FileDescription: Normal Directory MFC Application
FileVersion: 1, 0, 0, 1
InternalName: Normal Directory
LegalCopyright: Copyright (C) 2009
LegalTrademarks:
OriginalFilename: Normal Directory.EXE
ProductName: Normal Directory Application
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Worm:Win32/Folstart!pz also known as:

tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner.18119
MicroWorld-eScanTrojan.Agent.GEWD
FireEyeGeneric.mg.4c0d65f61285397b
CAT-QuickHealW32.Virut.D
ALYacTrojan.Agent.GEWD
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Agent.GEWD
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005a81c81 )
AlibabaWorm:Win32/FolStart.3ae5bf82
K7GWTrojan ( 005a81c81 )
Cybereasonmalicious.09da45
BitDefenderThetaGen:NN.ZexaF.36662.py0@a0nEsIgj
VirITWin32.Cheburgen.A
CyrenW32/Agent.CAA.gen!Eldorado
SymantecW32.Rotinom
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.NOM
APEXMalicious
ClamAVWin.Trojan.Virut-30
KasperskyHEUR:Worm.Win32.FolStart.pef
BitDefenderTrojan.Agent.GEWD
NANO-AntivirusTrojan.Win32.Cossta.ddawwa
SUPERAntiSpywareTrojan.Agent/Gen-Autorun
AvastWin32:Agent-ANIM [Trj]
TencentWorm.Win32.AutoRun.h
EmsisoftTrojan.Agent.GEWD (B)
F-SecureWorm.WORM/Agent.ctcsg
BaiduWin32.Worm.Agent.fc
ZillyaWorm.Agent.Win32.217428
TrendMicroWorm.Win32.FOLDRUN.SMA
McAfee-GW-EditionBehavesLike.Win32.Autorun.dz
Trapminemalicious.high.ml.score
SophosMal/Behav-043
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.19L4SV3
JiangminWorm/AutoRun.lox
GoogleDetected
AviraWORM/Agent.ctcsg
MAXmalware (ai score=100)
Antiy-AVLVirus/Win32.Expiro.ropf
XcitiumWorm.Win32.Agent.NEC0@1lq821
ArcabitTrojan.Agent.GEWD
ZoneAlarmHEUR:Worm.Win32.FolStart.pef
MicrosoftWorm:Win32/Folstart!pz
CynetMalicious (score: 99)
McAfeeW32/Autorun.worm.nm
TACHYONTrojan/W32.Agent.249856.AQL
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.36734
TrendMicro-HouseCallWorm.Win32.FOLDRUN.SMA
RisingWorm.Autorun!1.DD90 (CLASSIC)
YandexTrojan.GenAsa!yCCNvkncd1Y
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Wacatac.B!tr
AVGWin32:Agent-ANIM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Folstart!pz?

Worm:Win32/Folstart!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment