Worm

How to remove “Worm:Win32/Mofksys!pz”?

Malware Removal

The Worm:Win32/Mofksys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Mofksys!pz?


File Info:

name: E9F3D0DC9BBF31ECC48F.mlw
path: /opt/CAPEv2/storage/binaries/0750baa98bac96343c54564e7cc22054286678ec84f6a8b283c5188c4bf8ec13
crc32: 23740E34
md5: e9f3d0dc9bbf31ecc48fb083250fe1df
sha1: 044bab2469c47d593710c5eb43737e96878ff46b
sha256: 0750baa98bac96343c54564e7cc22054286678ec84f6a8b283c5188c4bf8ec13
sha512: 87bff5541e70f4acb4fc5b516dfb307a7ae50523617585b9029ac4bb5b67eac5dbe1c12d84e56f96d37845e322ebd7dfda8461cf10d3ccc3067e7985e9ac6252
ssdeep: 1536:UfsEqouTRcG/Mzvgf7xEuvnXNTRdUzwTekUOisZ1yDDajtXbVvUE:UVqoCl/YgjxEufVU0TbTyDDal1UE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T177D3E933FD14646ED921CAF038B6E66AFA111E7A4BA06C476261FF44367620379F130B
sha3_384: 71b1dcdcd790a74d375c7f3f6579ed6d48bdc046c9c2e50ae3befaa89dfb016ef4bb316059a64f5d5a1ab73cbb9f05c2
ep_bytes: 68dc3a4000e8eeffffff000048000000
timestamp: 2013-04-01 07:08:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: TJprojMain
OriginalFilename: TJprojMain.exe

Worm:Win32/Mofksys!pz also known as:

BkavW32.WatermarkHQc.PE
LionicTrojan.Win32.Agent.tnrh
Elasticmalicious (high confidence)
ClamAVWin.Trojan.VBGeneric-6735875-0
CAT-QuickHealW32.Mofksys.A4
SkyhighBehavesLike.Win32.Swisyn.cm
ALYacWin32.Gosys.B
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Gosys.B
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Mofksys.384
K7GWTrojan ( 0058e74a1 )
K7AntiVirusVirus ( 00579e181 )
BaiduWin32.Worm.VB.b
VirITTrojan.Win32.Agent4.ALYU
SymantecW32.Gosys
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.NBI
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.VB.mz
BitDefenderWin32.Gosys.B
NANO-AntivirusTrojan.Win32.Swisyn.flhacn
MicroWorld-eScanWin32.Gosys.B
RisingTrojan.Agent!1.6A70 (CLASSIC)
EmsisoftWin32.Gosys.B (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLP.Swisyn
ZillyaVirus.HLLP.Win32.1
TrendMicroPE_SWISB.A-O
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e9f3d0dc9bbf31ec
SophosTroj/Agent-ABZF
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.hxgb
WebrootW32.Trojan.Gen
VaristW32/Trojan.UEJO-9077
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Agent
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Mofksys!pz
XcitiumTrojWare.Win32.VB.QOTY@4qfd0g
ArcabitWin32.Gosys.B
ZoneAlarmVirus.Win32.VB.mz
GDataWin32.Trojan.PSE1.1NLNP9O
GoogleDetected
AhnLab-V3Worm/Win32.Mofksys.R198176
Acronissuspicious
McAfeeW32/Swisyn.b
TACHYONWorm/W32.VB-Mofksys.Zen
DeepInstinctMALICIOUS
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Spy.AT
ZonerTrojan.Win32.88925
TrendMicro-HouseCallPE_SWISB.A-O
TencentWorm.Win32.Wbna.wf
YandexTrojan.GenAsa!182yZo+3+DM
IkarusWorm.Mofksys
MaxSecureVirus.W32.Agent.xjgj
FortinetW32/VB.QCC!tr.dldr
BitDefenderThetaAI:Packer.FB4C4F7A20
AVGWin32:VB-OJQ [Wrm]
Cybereasonmalicious.469c47
AvastWin32:VB-OJQ [Wrm]

How to remove Worm:Win32/Mofksys!pz?

Worm:Win32/Mofksys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment