Worm

Worm:Win32/Mofksys.C (file analysis)

Malware Removal

The Worm:Win32/Mofksys.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys.C virus can do?

  • Executable code extraction
  • Anomalous binary characteristics

How to determine Worm:Win32/Mofksys.C?


File Info:

crc32: C27B49BF
md5: cb6ebeecbdec636c988448b32eba0857
name: CB6EBEECBDEC636C988448B32EBA0857.mlw
sha1: be6eb593d7a92970c9be1b01e428c008197141da
sha256: 48d2ac9b29e793ae84a8147260f74db278c9407853142584a7e109d5c335a80f
sha512: f853fa9188b73faa7adb6af0140e9edd3672b2a8d3817f490ca9542fcf014e95e244a19bcbe145c091fb6bcffe2d03e85cbbb15e1d1344fcdb174553a1769210
ssdeep: 1536:n4iA4UFVV+NVeTHNqIWKtIhXayH3l2TKjpX4iImVYpVcOB3IWVPd9:4eyVVKVe7NqDlhXaygCpXamVwcOdfT9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: KLprojMain
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Win
ProductVersion: 1.00
OriginalFilename: KLprojMain.exe

Worm:Win32/Mofksys.C also known as:

BkavW32.AIDetect.malware1
K7AntiVirusP2PWorm ( 004d58c41 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen5.44989
CynetMalicious (score: 100)
CAT-QuickHealW32.Mofksys.A4
McAfeeW32/Swisyn.ah
CylanceUnsafe
ZillyaTrojan.VB.Win32.113751
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWP2PWorm ( 004d58c41 )
Cybereasonmalicious.cbdec6
BaiduWin32.Worm.VB.b
CyrenW32/VB.JI.gen!Eldorado
ESET-NOD32a variant of Win32/VB.SZK
APEXMalicious
AvastWin32:VB-OJQ [Wrm]
ClamAVWin.Trojan.Agent-1130603
KasperskyTrojan-Ransom.Win32.Blocker.cjyk
BitDefenderGen:Variant.Ser.Razy.11071
NANO-AntivirusTrojan.Win32.Blocker.cqkxuv
SUPERAntiSpywareTrojan.Agent/Gen-VBQQC
MicroWorld-eScanGen:Variant.Ser.Razy.11071
TencentMalware.Win32.Gencirc.10b9fb91
Ad-AwareGen:Variant.Ser.Razy.11071
SophosML/PE-A + Mal/MsPoser-F
ComodoTrojWare.Win32.VB.qqc@52dxue
BitDefenderThetaAI:Packer.F6C81ABA20
VIPRETrojan.Win32.Generic!SB.0
TrendMicroPE_SWISB.A-O
McAfee-GW-EditionBehavesLike.Win32.Swisyn.cm
FireEyeGeneric.mg.cb6ebeecbdec636c
EmsisoftGen:Variant.Ser.Razy.11071 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.aywiq
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MicrosoftWorm:Win32/Mofksys.C
ZoneAlarmTrojan-Ransom.Win32.Blocker.cjyk
GDataGen:Variant.Ser.Razy.11071
AhnLab-V3Trojan/Win32.Swisyn.R1452
VBA32Hoax.Blocker
MAXmalware (ai score=87)
MalwarebytesBackdoor.Agent.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallPE_SWISB.A-O
RisingTrojan.QOT!1.6519 (CLASSIC)
YandexTrojan.GenAsa!xoJgsb7u+Gs
IkarusTrojan.Win32.VB
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/VB.QQC!tr
AVGWin32:VB-OJQ [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.ad7

How to remove Worm:Win32/Mofksys.C?

Worm:Win32/Mofksys.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment