Worm

Worm:Win32/Mofksys.B removal tips

Malware Removal

The Worm:Win32/Mofksys.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys.B virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Worm:Win32/Mofksys.B?


File Info:

crc32: D47C5A45
md5: 22e1775cd502fb3f0b2d6793b5804392
name: flashplayer.exe
sha1: 5eab9b318d026d65bc8373234941c4539fd40f1f
sha256: 6eb51180b5237e0c7490e7e7b459f5fe30877faea1b724b2271c5e7c58c985e5
sha512: 7915d3ad6ef339b2e3200bc039e7d57aa636b41827273d9be59301e74f6083acf8534410cb4900dc1434d27c458c1e7284c4745dc1909f7a81e98d0dab8b1e05
ssdeep: 98304:2OLrUwbRsc8HGZlbrQGmjb6XPpPLyMUCok4iWBzxiwOy:20Uw8mj4xjbgLyMSkdWBzxiwX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: TJprojMain
FileVersion: 1.00
OriginalFilename: TJprojMain.exe
ProductName: Project1

Worm:Win32/Mofksys.B also known as:

BkavW32.WatermarkHQc.PE
MicroWorld-eScanGen:Variant.Midie.9550
FireEyeGeneric.mg.22e1775cd502fb3f
CAT-QuickHealW32.Mofksys.A4
Qihoo-360HEUR/QVM03.0.112F.Malware.Gen
McAfeeW32/Swisyn.b
CylanceUnsafe
VIPRETrojan.Win32.Agent.abzf (v)
AegisLabTrojan.Win32.Agent.tnrh
SangforMalware
K7AntiVirusP2PWorm ( 00526bf61 )
BitDefenderGen:Variant.Midie.9550
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
BaiduWin32.Worm.VB.b
F-ProtW32/Trojan2.PWYM
SymantecW32.Gosys!gen1
TotalDefenseWin32/Tnega.SHMfXW
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.VBGeneric-6735875-0
GDataGen:Variant.Midie.9550
KasperskyTrojan.Win32.Agent.xjgj
AlibabaWorm:Win32/Mofksys.5b326ca8
NANO-AntivirusTrojan.Win32.Swisyn.flhacn
RisingTrojan.Agent!1.6A70 (CLOUD)
Ad-AwareGen:Variant.Midie.9550
SophosTroj/Agent-ABZF
ComodoTrojWare.Win32.VB.QOTY@4qfd0g
F-SecureWorm.WORM/Mofksys.bouem
DrWebWin32.HLLP.Swisyn
ZillyaVirus.HLLP.Win32.1
TrendMicroPE_SWISB.A
McAfee-GW-EditionBehavesLike.Win32.Swisyn.wc
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Agent!O
EmsisoftGen:Variant.Midie.9550 (B)
IkarusWorm.Mofksys
CyrenW32/Trojan.UEJO-9077
JiangminTrojan/Agent.hxgb
WebrootW32.Malware.Gen
AviraWORM/Mofksys.bouem
Endgamemalicious (high confidence)
ArcabitTrojan.Midie.D254E
ZoneAlarmTrojan.Win32.Agent.xjgj
MicrosoftWorm:Win32/Mofksys.B
AhnLab-V3Trojan/Win32.Swisyn.R1452
Acronissuspicious
ALYacGen:Variant.Midie.9550
MAXmalware (ai score=83)
VBA32TScope.Trojan.VB
MalwarebytesTrojan.Dropper
PandaTrj/Spy.AT
ESET-NOD32Win32/VB.OOF
TrendMicro-HouseCallPE_SWISB.A
TencentTrojan.Win32.Agent.ade
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/VB.QCC!tr.dldr
AVGWin32:VB-OJQ [Wrm]
Cybereasonmalicious.cd502f
AvastWin32:VB-OJQ [Wrm]
MaxSecureVirus.W32.Agent.xjgj

How to remove Worm:Win32/Mofksys.B?

Worm:Win32/Mofksys.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment