Worm

Worm:Win32/Mofksys!pz information

Malware Removal

The Worm:Win32/Mofksys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Mofksys!pz?


File Info:

name: 2691FC4B6FB38EAE1E37.mlw
path: /opt/CAPEv2/storage/binaries/c7ed9bfe8f04a32d3b4d8a4158dd1a1345f845778841ea66a6c58f5285a98cf8
crc32: 97647499
md5: 2691fc4b6fb38eae1e37d97420505e88
sha1: 4d6bf23d7a95098945b0e35c626f802ed1e549bd
sha256: c7ed9bfe8f04a32d3b4d8a4158dd1a1345f845778841ea66a6c58f5285a98cf8
sha512: 23195898bf937b5fb6faa78a01df0f6764eb4e523bd19e5becc578a5d4e21c43e1c793375383d3c1cc6c4f91515b086f7f3ca7b11cef895b6a6d0d854e43fcca
ssdeep: 49152:3LgQDnkLpxaVh9mgO1+OgoeeSvgBJLiyOlEpMjwiV/iV:vCGrptrbguyOw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EE5CE037954CE46F03947F4F90609F82B2A6E28E6B1B6AF55717DDB3C203825D4E62B
sha3_384: a99c245b8dfb33e45a2e9b50ebe48b90ce991afe4cd53c674ef81525a8b4e86f565d3585447410d1e02dddabcd152c18
ep_bytes: 68dc3a4000e8eeffffff000048000000
timestamp: 2013-04-01 07:08:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: TJprojMain
OriginalFilename: TJprojMain.exe

Worm:Win32/Mofksys!pz also known as:

BkavW32.WatermarkHQc.PE
ElasticWindows.Generic.Threat
DrWebWin32.HLLP.Swisyn
MicroWorld-eScanWin32.Gosys.B
FireEyeGeneric.mg.2691fc4b6fb38eae
CAT-QuickHealW32.Mofksys.A4
SkyhighBehavesLike.Win32.Swisyn.wc
McAfeeW32/Swisyn.b
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Gosys.B
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00579e181 )
K7GWVirus ( 00579e181 )
Cybereasonmalicious.d7a950
ArcabitWin32.Gosys.B
BitDefenderThetaGen:NN.ZevbaF.36744.gp3@a4zr1tci
VirITTrojan.Win32.Agent4.ALYU
SymantecW32.Gosys!gen1
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.NBI
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VBGeneric-6735875-0
KasperskyVirus.Win32.VB.mz
BitDefenderWin32.Gosys.B
NANO-AntivirusTrojan.Win32.Swisyn.flhacn
AvastWin32:VB-OJQ [Wrm]
TencentWorm.Win32.Wbna.wf
EmsisoftWin32.Gosys.B (B)
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Worm.VB.b
ZillyaVirus.HLLP.Win32.1
TrendMicroPE_SWISB.A
Trapminemalicious.high.ml.score
SophosTroj/Agent-ABZF
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.hxgb
WebrootW32.Malware.Gen
VaristW32/Trojan.UEJO-9077
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Agent
XcitiumTrojWare.Win32.VB.QOTY@4qfd0g
MicrosoftWorm:Win32/Mofksys!pz
ZoneAlarmVirus.Win32.VB.mz
GDataWin32.Trojan.PSE1.C4EPE9
GoogleDetected
AhnLab-V3Trojan/Win32.Swisyn.R254290
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacWin32.Gosys.B
TACHYONWorm/W32.VB-Mofksys.Zen
Cylanceunsafe
PandaTrj/Spy.AT
ZonerTrojan.Win32.88925
TrendMicro-HouseCallPE_SWISB.A
RisingTrojan.Agent!1.6A70 (CLASSIC)
YandexTrojan.GenAsa!182yZo+3+DM
IkarusWorm.Mofksys
MaxSecureVirus.W32.Agent.xjgj
FortinetW32/VB.QCC!tr.dldr
AVGWin32:VB-OJQ [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Mofksys!pz?

Worm:Win32/Mofksys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment