Worm

Should I remove “Worm:Win32/Mofksys!pz”?

Malware Removal

The Worm:Win32/Mofksys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Mofksys!pz?


File Info:

name: E748061CBE7E825BA125.mlw
path: /opt/CAPEv2/storage/binaries/38d9fc71ee4ac939e51c47a0ed1ed66ed380fe4b49adf1b3ae240c3f363dab80
crc32: A0565F14
md5: e748061cbe7e825ba1256bea33c020c2
sha1: be7ba53429b86b4eccaf9db84e1ea2aa4063c366
sha256: 38d9fc71ee4ac939e51c47a0ed1ed66ed380fe4b49adf1b3ae240c3f363dab80
sha512: 30e3117c822b7a80aff5b1814119af267a35bba572c5e67a7f472f28aee0bb6b0fa9ecf3b167ac5908231b207ad45a3c73aea86dcd6566e1e88b3211364b2a78
ssdeep: 1536:UfsEqouTRcG/Mzvgf7xEuvnXNTRdUzwTekUOisZ1yDDajtXbVvUK:UVqoCl/YgjxEufVU0TbTyDDal1UK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136D31B337E10542ED962C6F02CB5E76ABA221F251B95AE577366BB01313628375F230F
sha3_384: 0fcf5ad9668a913cbda5ca7227f78c0418b7809117125dceebd80b676fc05d94b5e41647c0e1f657ed2db65b8bf1ea77
ep_bytes: 68dc3a4000e8eeffffff000048000000
timestamp: 2013-04-01 07:08:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: TJprojMain
OriginalFilename: TJprojMain.exe

Worm:Win32/Mofksys!pz also known as:

BkavW32.WatermarkHQc.PE
MicroWorld-eScanWin32.Gosys.B
FireEyeGeneric.mg.e748061cbe7e825b
CAT-QuickHealW32.Mofksys.A4
SkyhighBehavesLike.Win32.Swisyn.cm
McAfeeW32/Swisyn.b
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.HLLP.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0058e74a1 )
K7AntiVirusVirus ( 00579e181 )
BitDefenderThetaAI:Packer.FB4C4F7A20
VirITTrojan.Win32.Agent4.ALYU
SymantecW32.Gosys
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.NBI
APEXMalicious
ClamAVWin.Trojan.VBGeneric-6735875-0
KasperskyVirus.Win32.VB.mz
BitDefenderWin32.Gosys.B
NANO-AntivirusTrojan.Win32.Swisyn.flhacn
AvastWin32:VB-OJQ [Wrm]
TencentWorm.Win32.Wbna.wf
SophosTroj/Agent-ABZF
BaiduWin32.Worm.VB.b
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLP.Swisyn
VIPREWin32.Gosys.B
TrendMicroPE_SWISB.A-O
Trapminemalicious.high.ml.score
EmsisoftWin32.Gosys.B (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
GDataWin32.Trojan.PSE1.1NLNP9O
JiangminTrojan/Agent.hxgb
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Patched.Ren.Gen
VaristW32/Trojan.UEJO-9077
Antiy-AVLTrojan/Win32.Agent
XcitiumTrojWare.Win32.VB.QOTY@4qfd0g
ArcabitWin32.Gosys.B
ZoneAlarmVirus.Win32.VB.mz
MicrosoftWorm:Win32/Mofksys!pz
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Mofksys.R198176
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacWin32.Gosys.B
TACHYONWorm/W32.VB-Mofksys.Zen
Cylanceunsafe
PandaTrj/Spy.AT
ZonerTrojan.Win32.88925
TrendMicro-HouseCallPE_SWISB.A-O
RisingTrojan.Agent!1.6A70 (CLASSIC)
YandexTrojan.GenAsa!182yZo+3+DM
IkarusWorm.Mofksys
FortinetW32/VB.QCC!tr.dldr
AVGWin32:VB-OJQ [Wrm]
Cybereasonmalicious.429b86
DeepInstinctMALICIOUS

How to remove Worm:Win32/Mofksys!pz?

Worm:Win32/Mofksys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment