Worm

Worm:Win32/Korgo.S removal

Malware Removal

The Worm:Win32/Korgo.S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Korgo.S virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Korgo.S?


File Info:

name: F1D0BD6D831F57F09C44.mlw
path: /opt/CAPEv2/storage/binaries/bd5dbc2e086daebfbb3a5ed15f69ce8cb7317b7ab1e29bc901e8b128fac05bc7
crc32: CAF1FA2F
md5: f1d0bd6d831f57f09c4442e4d004752d
sha1: 00bb9bda4093e71e505d10269e7eca1284af969a
sha256: bd5dbc2e086daebfbb3a5ed15f69ce8cb7317b7ab1e29bc901e8b128fac05bc7
sha512: 2571dbe959e11289964021e0ed18057f8fda09658799d6f0defc9c3f23d0d951686654515981e6ffdf2b8676e06f705a98b6dcd8a2f9fc2bc05bf18b02b9250e
ssdeep: 384:TyY8lFdzCTf+6e2RBTw9JJO1cLL5Bp03aC3psJyv2q:TyY8xeFWTk1cxBp0KC3kW2q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18972C0CE8C3ECD00E04917BEC16B5F147058B541717ABB5FE1355822592BA4F8DCDAEA
sha3_384: 40c8365b951d50abaf8261f5c305d74299ed132c490bd13c61a09882fe810e53447288f48a7b98ed784546b9db16baa7
ep_bytes: e800000000558b5c24088b6c2404816c
timestamp: 2004-06-18 17:33:17

Version Info:

0: [No Data]

Worm:Win32/Korgo.S also known as:

BkavW32.FemaRub.PE
Elasticmalicious (moderate confidence)
MicroWorld-eScanWin32.Generic.4145
FireEyeGeneric.mg.f1d0bd6d831f57f0
CAT-QuickHealW32.Virut.F
SkyhighBehavesLike.Win32.Mydoom.lc
ALYacWin32.Generic.4145
Cylanceunsafe
ZillyaVirus.Virut.Win32.1
SangforVirus_Suspicious.Win32.Virut.b
K7AntiVirusVirus ( 00001b6b1 )
AlibabaVirus:Win32/Virut.44cfd0de
K7GWVirus ( 00001b6b1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitWin32.Generic.4145
BitDefenderThetaAI:FileInfector.1E3F74C612
VirITWin32.Virut.A
SymantecW32.Korgo.S
ESET-NOD32Win32/Virut.5127
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Virut-14
KasperskyVirus.Win32.Virut.a
BitDefenderWin32.Generic.4145
NANO-AntivirusVirus.Win32.Virut.jxol
AvastWin32:Korgo-S [Wrm]
TencentVirus.Win32.Virut.aa
TACHYONVirus/W32.Virut.Gen
SophosW32/Virut-T
BaiduWin32.Virus.Virut.b
F-SecureMalware.W32/Virut.Gen
DrWebWin32.Lsabot
VIPREWin32.Generic.4145
TrendMicroPE_VIRUT.A
EmsisoftWin32.Generic.4145 (B)
IkarusWorm.Win32.Korgo
JiangminWin32/Virut.a
WebrootW32.Worm.Korgo.Gen
VaristW32/Virut.4960
AviraW32/Virut.Gen
Antiy-AVLVirus/Win32.Virut.a
KingsoftWin32.Virut.a.8192
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftWorm:Win32/Korgo.S
ViRobotWin32.Virut.Gen.A
ZoneAlarmVirus.Win32.Virut.a
GDataWin32.Virus.Virut.D
GoogleDetected
AhnLab-V3Win32/Virut
McAfeeW32/Virut.b.a
MAXmalware (ai score=100)
VBA32Virus.Win32.Virut.A
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Virutas.B
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPE_VIRUT.A
RisingVirus.Virut!1.A08B (CLASSIC)
YandexTrojan.GenAsa!APUjCodU+1s
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Virut
FortinetW32/Padobot!worm.im
AVGWin32:Korgo-S [Wrm]
Cybereasonmalicious.a4093e
DeepInstinctMALICIOUS

How to remove Worm:Win32/Korgo.S?

Worm:Win32/Korgo.S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment