Worm

Worm:Win32/Mofksys!pz (file analysis)

Malware Removal

The Worm:Win32/Mofksys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Mofksys!pz?


File Info:

name: 55BD76DA0884257213A5.mlw
path: /opt/CAPEv2/storage/binaries/a8f58daf3eb0ac4e1862f9c86ddfb60e1b57c4f1c85a03220a05aeeaa9c05249
crc32: 8112EB80
md5: 55bd76da0884257213a500f564502ec1
sha1: 4fa9d91f938fc55b5a890ad36f7238734d25ce74
sha256: a8f58daf3eb0ac4e1862f9c86ddfb60e1b57c4f1c85a03220a05aeeaa9c05249
sha512: 13e024d8a85d7eca59c4d59c475a6a53a96a8618f411693563a24be399a78093f963fbed6ab53f685d2f0d70ad6caf5d83aee8a6b5992430017fd12a14b1ae57
ssdeep: 1536:GfsEqouTRcG/Mzvgf7xEuvnXNTRdUzwTekUOisZ1yDDajtXbJdo:GVqoCl/YgjxEufVU0TbTyDDalbo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F124F867AE21905EF41549F698B4D51BFC66AE395BF5AC0BE242BB002573203B1FC31B
sha3_384: e2ba26a97a9715c3d4ccac3467e1d569309256245aeac07ed40d6dcd19c651a64b247917d8305def85f6bdddc95aa1fa
ep_bytes: 68dc3a4000e8eeffffff000048000000
timestamp: 2013-04-01 07:08:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: TJprojMain
OriginalFilename: TJprojMain.exe

Worm:Win32/Mofksys!pz also known as:

BkavW32.WatermarkHQc.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Gosys.B
ClamAVWin.Trojan.VBGeneric-6735875-0
FireEyeGeneric.mg.55bd76da08842572
CAT-QuickHealW32.Mofksys.A4
SkyhighBehavesLike.Win32.Swisyn.dt
ALYacWin32.Gosys.B
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.HLLP.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00579e181 )
K7GWVirus ( 00579e181 )
Cybereasonmalicious.f938fc
BitDefenderThetaAI:Packer.BB9602BE20
VirITTrojan.Win32.Agent4.ALYU
SymantecW32.Gosys!gen1
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.NBI
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.xadzcg
BitDefenderWin32.Gosys.B
NANO-AntivirusTrojan.Win32.Swisyn.flhacn
AvastWin32:VB-OJQ [Wrm]
TencentWorm.Win32.Wbna.wf
EmsisoftWin32.Gosys.B (B)
BaiduWin32.Worm.VB.b
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLP.Swisyn
VIPREWin32.Gosys.B
TrendMicroPE_SWISB.A-O
SophosTroj/Agent-ABZF
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.hxgb
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Win32.Agent
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Mofksys!pz
XcitiumTrojWare.Win32.VB.QOTY@4qfd0g
ArcabitWin32.Gosys.B
ZoneAlarmTrojan.Win32.Agent.xadzcg
GDataWin32.Trojan.PSE1.C4EPE9
VaristW32/Trojan.UEJO-9077
AhnLab-V3Trojan/Win32.Swisyn.R254290
Acronissuspicious
McAfeeW32/Swisyn.b
TACHYONWorm/W32.VB-Mofksys.Zen
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Spy.AT
ZonerTrojan.Win32.88925
TrendMicro-HouseCallPE_SWISB.A-O
RisingTrojan.Agent!1.6A70 (CLASSIC)
YandexTrojan.GenAsa!182yZo+3+DM
IkarusWorm.Mofksys
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.QCC!tr.dldr
AVGWin32:VB-OJQ [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Mofksys!pz?

Worm:Win32/Mofksys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment