Worm

Worm:Win32/Mofksys!pz removal

Malware Removal

The Worm:Win32/Mofksys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the RustyStealer malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Mofksys!pz?


File Info:

name: 4D2FB0A1DBE621D880FA.mlw
path: /opt/CAPEv2/storage/binaries/2cc1499b836095e35890ab6e24d15542b6df21ba63ececcae58d9b57a782a1fb
crc32: 06AA889C
md5: 4d2fb0a1dbe621d880fa4602b652cf2d
sha1: 9a46f9e82c181ce388b234a29b18fcf91f875b1a
sha256: 2cc1499b836095e35890ab6e24d15542b6df21ba63ececcae58d9b57a782a1fb
sha512: efb11f93fb758fc176883a10065b5d941e72e4a306f10da3702dae48ef1f6bf44cba76267b97985ce20565997c8a2f1b10423221fa1d02aeb991a6c5946f6e51
ssdeep: 49152:mJZoQrbTFZY1iaO4ROX1lW68ZM5mmhD+SbilzCUWCLcMldpxruKihtKUoy+XCBe4:mtrbTA18XLW6jRhdGVQguhhW31ZX7nGd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196262312F1C6903AD2F327B15DBDF36A963969351326D29723C42E316EE05812F2A773
sha3_384: 374bb78af78aca595f88ce93353a645839db8715a930fae7923e0312aa09005a03f9ea7bf9f1c0e653503c0074da093a
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Worm:Win32/Mofksys!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.4018
FireEyeGeneric.mg.4d2fb0a1dbe621d8
CAT-QuickHealTrojan.Mofksys.A
SkyhighBehavesLike.Win32.Dropper.rc
ALYacWin32.Gosys.A
MalwarebytesGeneric.Trojan.Malicious.DDS
SangforTrojan.Win32.Save.a
BitDefenderAIT:Trojan.Nymeria.4018
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36792.@p3@aOYPykgi
SymantecTrojan.Gen.9
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Malware.Autoit-6912463-0
KasperskyTrojan-Dropper.Win32.Autoit.abceqi
NANO-AntivirusTrojan.Win32.Swisyn.efyboj
RisingTrojan.VB!1.6519 (CLASSIC)
SophosGeneric ML PUA (PUA)
BaiduWin32.Trojan.VB.at
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.Siggen6.54687
VIPREAIT:Trojan.Nymeria.4018
TrendMicroPE_MOFKSYS.A
Trapminemalicious.moderate.ml.score
EmsisoftAIT:Trojan.Nymeria.4018 (B)
IkarusTrojan-Spy.MSIL.Omaneat
GoogleDetected
AviraTR/Patched.Ren.Gen
VaristW32/VB.RBGG-8488
Antiy-AVLTrojan/Win32.Swisyn.bner
Kingsoftmalware.kb.a.970
MicrosoftWorm:Win32/Mofksys!pz
ArcabitAIT:Trojan.Nymeria.DFB2 [many]
ZoneAlarmTrojan-Dropper.Win32.Autoit.abceqi
GDataWin32.Gosys.A (2x)
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!4D2FB0A1DBE6
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
VBA32Trojan.Autoit.F
Cylanceunsafe
TrendMicro-HouseCallPE_MOFKSYS.A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Autoit.AZA
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.82c181
AvastScript:SNH-gen [Trj]

How to remove Worm:Win32/Mofksys!pz?

Worm:Win32/Mofksys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment