Worm

What is “Worm:Win32/Mofksys!pz”?

Malware Removal

The Worm:Win32/Mofksys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Mofksys!pz?


File Info:

name: 33F32386CD67A7202B7D.mlw
path: /opt/CAPEv2/storage/binaries/881845ae501c84103247b6cb593e8dc1359588c2c9a9048706b818cd19100bf9
crc32: 612DF6AC
md5: 33f32386cd67a7202b7d492478da03d3
sha1: 5aca643800770138e1d55beb9940d3163865230c
sha256: 881845ae501c84103247b6cb593e8dc1359588c2c9a9048706b818cd19100bf9
sha512: f5306b2be3ac2f58ddeebb46ff95905cd02cbf052f6f50738107c231d1a5c79c3a090793b0a9c36a8e629d0362beebcd081f09a93d46b5733203a8ac9e0425c2
ssdeep: 1536:UfsEqouTRcG/Mzvgf7xEuvnXNTRdUzwTekUOisZ1yDDajtXbV7yrgrrrrrrrrrrm:UVqoCl/YgjxEufVU0TbTyDDaluH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190D3F7277E60102EDD128AF568A5DB6EB9615F361BE0AC0BB3A2FB44257114376F031F
sha3_384: 4eb74574c6422bd8b78ad99e43cdbdf0d839125a741afe3b82d17e225f7451473b7b89c1763a3190cf08989f232cc661
ep_bytes: 68dc3a4000e8eeffffff000048000000
timestamp: 2013-04-01 07:08:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: TJprojMain
OriginalFilename: TJprojMain.exe

Worm:Win32/Mofksys!pz also known as:

BkavW32.WatermarkHQc.PE
DrWebWin32.HLLP.Swisyn
MicroWorld-eScanWin32.Gosys.B
FireEyeGeneric.mg.33f32386cd67a720
CAT-QuickHealW32.Mofksys.A4
SkyhighBehavesLike.Win32.Swisyn.cm
McAfeeW32/Swisyn.b
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.HLLP.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00579e181 )
K7GWTrojan ( 0058e74a1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Gosys.B
BitDefenderThetaAI:Packer.FB4C4F7A20
VirITTrojan.Win32.Agent4.ALYU
SymantecW32.Gosys
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.NBI
APEXMalicious
ClamAVWin.Malware.Generickdz-9937235-0
KasperskyVirus.Win32.VB.mz
BitDefenderWin32.Gosys.B
NANO-AntivirusTrojan.Win32.Swisyn.flhacn
AvastWin32:VB-OJQ [Wrm]
RisingTrojan.Agent!1.6A70 (CLASSIC)
SophosTroj/Agent-ABZF
GoogleDetected
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Worm.VB.b
VIPREWin32.Gosys.B
TrendMicroPE_SWISB.A-O
Trapminemalicious.high.ml.score
EmsisoftWin32.Gosys.B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.hxgb
WebrootW32.Trojan.Gen
VaristW32/Trojan.UEJO-9077
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Agent
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.QOTY@4qfd0g
MicrosoftWorm:Win32/Mofksys!pz
ZoneAlarmVirus.Win32.VB.mz
GDataWin32.Trojan.PSE1.1NLNP9O
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Mofksys.R198176
Acronissuspicious
ALYacWin32.Gosys.B
TACHYONWorm/W32.VB-Mofksys.Zen
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Spy.AT
ZonerTrojan.Win32.88925
TrendMicro-HouseCallPE_SWISB.A-O
TencentWorm.Win32.Wbna.wf
IkarusWorm.Mofksys
FortinetW32/VB.QCC!tr.dldr
AVGWin32:VB-OJQ [Wrm]
Cybereasonmalicious.800770
DeepInstinctMALICIOUS

How to remove Worm:Win32/Mofksys!pz?

Worm:Win32/Mofksys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment