Worm

How to remove “Worm:Win32/Folxrun!pz”?

Malware Removal

The Worm:Win32/Folxrun!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Folxrun!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Worm:Win32/Folxrun!pz?


File Info:

name: 21C93F334EFD50C10E29.mlw
path: /opt/CAPEv2/storage/binaries/458499b0af14730ebbd1584fd115d8d98bbab1c067f477a297b079cd2700c278
crc32: 91D16C75
md5: 21c93f334efd50c10e294085f43a32c4
sha1: 3eb5edf4320633ece1ac91cb025b99c7df9fb6eb
sha256: 458499b0af14730ebbd1584fd115d8d98bbab1c067f477a297b079cd2700c278
sha512: fb43c8ee48f7723fad64f189c658692e76e8e3c10c33591e531e4eef7d31deb12b378b0ab9cce4532bcc7edde1afcc2f1de68ae8013d2a91ee282b61f61ee423
ssdeep: 3072:kM+c0uGUjcfquss7f8M+c0uGUjcfquss7fp32HjfrsDbj/f9sM+c0uGUjcfquAVp:R2hfqulp2hfqulJojfgDn12hfqu+pb7D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C264AE62F350A099D0A580F12052D679AA227C326089CD1BBBD5FF5F39312D7B2E5B1B
sha3_384: 9edba590add0fa215b5c21548e42effeb8d3020d672293d60bdb82289f147c94b76f48eed9e1f907b0c98ae59fb0ba2a
ep_bytes: 68c40f4100e8eeffffff000000000000
timestamp: 1997-07-14 03:30:03

Version Info:

0: [No Data]

Worm:Win32/Folxrun!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Rasith.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.TUD
CAT-QuickHealW32.Virut.G
SkyhighBehavesLike.Win32.VBObfus.fh
ALYacWin32.Worm.TUD
Cylanceunsafe
ZillyaWorm.Hesv.Win32.54
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 004d6bef1 )
AlibabaWorm:Win32/Folxrun.f873e0f8
K7GWTrojan ( 004d6bef1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Worm.TUD
BitDefenderThetaAI:Packer.EBFD6A431B
VirITWorm.Win32.X-Aurun.BRXZ
SymantecW32.Rasith
ESET-NOD32Win32/Rasith.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Rasith-6816112-0
KasperskyTrojan.Win32.Hesv.bjrj
BitDefenderWin32.Worm.TUD
NANO-AntivirusTrojan.Win32.Autoruner2.ewcqfg
AvastWin32:Vitro [Inf]
TencentTrojan.Win32.Hesv.a
EmsisoftWin32.Worm.TUD (B)
BaiduWin32.Trojan.VB.ja
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner2.29691
VIPREWin32.Worm.TUD
TrendMicroWorm.Win32.RASITH.SMCGR22
SophosMal/VB-F
IkarusTrojan.Patched
JiangminTrojan.Hesv.iyr
WebrootTrojan.Dropper.Gen
VaristW32/VB.ZO.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Win32.Rasith
KingsoftWin32.Trojan.Hesv.bjrj
XcitiumWorm.Win32.Rasith.A@85dnyp
MicrosoftWorm:Win32/Folxrun!pz
ZoneAlarmTrojan.Win32.Hesv.bjrj
GDataWin32.Worm.TUD
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Injector.R273295
McAfeeW32/Worm-FVM!21C93F334EFD
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
ZonerTrojan.Win32.97518
TrendMicro-HouseCallWorm.Win32.RASITH.SMCGR22
RisingWorm.Folxrun!1.A281 (CLASSIC)
YandexTrojan.GenAsa!WXDkHuHZCZs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11476848.susgen
FortinetW32/Rasith.A!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.432063
DeepInstinctMALICIOUS

How to remove Worm:Win32/Folxrun!pz?

Worm:Win32/Folxrun!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment