Worm

Worm:Win32/Korgo.AB malicious file

Malware Removal

The Worm:Win32/Korgo.AB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Korgo.AB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Korgo.AB?


File Info:

name: 6B209A06B76B89AC6D0C.mlw
path: /opt/CAPEv2/storage/binaries/ad4690e3a8e795e4efbde14c22ee07a1af5961d94c92afed39bbda7b044a1921
crc32: 1AC4B22C
md5: 6b209a06b76b89ac6d0ce002e18f22ae
sha1: f6786e72dacf39f7910c35ae4bc18c98ffaecf36
sha256: ad4690e3a8e795e4efbde14c22ee07a1af5961d94c92afed39bbda7b044a1921
sha512: 054c3c98808457bdaf36109d8542e8ca04344740e0a51d66c7431b02211b0c24a9904e45145a25ebec762fdfcf1103620799a274935d3432baa2fa0ca6a5e9a2
ssdeep: 384:T+2droL1yc57go/kwCErZ4Ej2V8x14/6+0F06PNuiaVEG5O08MZ+ETyJHT:YF57xMwCA4E6uzU6tb1uZEs8EG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1E2E11B96372835E5F6DD37D427295B7C9148508601DA348070E5EF7D3F22A3AAF3A4
sha3_384: 9f1c6d13050a001f5464c035ed2138155298ae1980e029d087f25db5c58205505e9672a44789d284c0560c6e3c61c2c8
ep_bytes: 29d229c9b1ac424975fce81c00000081
timestamp: 2004-06-28 20:25:54

Version Info:

0: [No Data]

Worm:Win32/Korgo.AB also known as:

BkavW32.Vetor.PE
LionicVirus.Win32.Virut.n!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.561840
FireEyeGeneric.mg.6b209a06b76b89ac
CAT-QuickHealW32.Virut.D
SkyhighW32/Virut.j.gen
McAfeeW32/Virut.j.gen
Cylanceunsafe
ZillyaVirus.Virut.Win32.6
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f10005011 )
AlibabaVirus:Win32/Virut.05eafbcd
K7GWTrojan ( f10005011 )
Cybereasonmalicious.6b76b8
BaiduWin32.Virus.Virut.i
VirITWorm.Win32.Korgo.D
SymantecW32.Virut.B
ESET-NOD32Win32/Virut.E
APEXMalicious
TrendMicro-HouseCallPE_VIRUT.D-1
AvastWin32:Korgo-T [Wrm]
ClamAVWin.Trojan.Virut-18
KasperskyVirus.Win32.Virut.n
BitDefenderTrojan.Generic.561840
NANO-AntivirusVirus.Win32.Virut.jxol
TencentVirus.Win32.HanKu.e
SophosW32/Virut-L
F-SecureMalware.W32/Virut.AT
DrWebWin32.Virut.5
VIPRETrojan.Generic.561840
TrendMicroPE_VIRUT.D-1
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.561840 (B)
IkarusWorm.Win32.Korgo
JiangminWin32/Virut.e
GoogleDetected
AviraW32/Virut.AT
VaristW32/Korgo.JFZI-5824
Antiy-AVLVirus/Win32.Virut.n
KingsoftWin32.Virut.F.121344
MicrosoftWorm:Win32/Korgo.AB
XcitiumVirus.Win32.Virut.q@1fhkey
ArcabitTrojan.Generic.D892B0
ViRobotWin32.Virut.Gen.B
ZoneAlarmVirus.Win32.Virut.n
GDataTrojan.Generic.561840
CynetMalicious (score: 100)
AhnLab-V3Win32/Virut.D
BitDefenderThetaAI:FileInfector.D6DFFBB612
ALYacTrojan.Generic.561840
MAXmalware (ai score=100)
VBA32Virus.Virut.07
MalwarebytesMalware.AI.3796222575
PandaW32/Virutas.gen
ZonerProbably Heur.ExeHeaderL
RisingVirus.Virut!1.A08C (CLASSIC)
YandexTrojan.GenAsa!XSnf3eT+w8U
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Bluwin.A
FortinetW32/MetaCrypt.1
AVGWin32:Korgo-T [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudVirus:Win/Virut.E

How to remove Worm:Win32/Korgo.AB?

Worm:Win32/Korgo.AB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment