Worm

Worm:Win32/Mofksys!pz removal tips

Malware Removal

The Worm:Win32/Mofksys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mofksys!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Mofksys!pz?


File Info:

name: 3E4AE2991CC5C62E7306.mlw
path: /opt/CAPEv2/storage/binaries/40512f55a49921283d1c3025e85c814c6992fe34ac99192b7c4de98a90345cbe
crc32: C3D7E315
md5: 3e4ae2991cc5c62e73065997ad94235c
sha1: c9e7a82fff78cf64bfd56f86b4bae5ccc4530453
sha256: 40512f55a49921283d1c3025e85c814c6992fe34ac99192b7c4de98a90345cbe
sha512: 404626b300537c605936f91d65577351d4d0cc11d43aef55a8413fe800d5774b42a30334c8fa58c8cfc4371490d1c4d7cfe3c7f86c0ba7b2251261ba5b82ad29
ssdeep: 24576:PFOaPyySS4LEHD+EsTr7i6SK+6hHi7qo79Vkc:tzrhwr7iJ9qHiug3kc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE458D217A95C53FEA930573CA7DAB5E2119ED320B2459C7B2C81A5C5E706C37E3A30B
sha3_384: 217bcc9e3569b6389a9e2e2ffd3579da09614e15b4a990f50a3c37afa599985eaddb5f95bf5c540b5f5dfc3f7dc37140
ep_bytes: 68dc3a4000e8eeffffff000048000000
timestamp: 2013-04-01 07:08:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: TJprojMain
OriginalFilename: TJprojMain.exe

Worm:Win32/Mofksys!pz also known as:

BkavW32.WatermarkHQc.PE
AVGWin32:VB-OJQ [Wrm]
tehtrisGeneric.Malware
MicroWorld-eScanWin32.Gosys.B
FireEyeGeneric.mg.3e4ae2991cc5c62e
CAT-QuickHealW32.Mofksys.A4
SkyhighBehavesLike.Win32.Swisyn.th
McAfeeW32/Swisyn.b
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Gosys.B
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00579e181 )
K7GWTrojan ( 0058e74a1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitWin32.Gosys.B
BaiduWin32.Worm.VB.b
VirITTrojan.Win32.Agent4.ALYU
SymantecW32.Gosys
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.NBI
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VBGeneric-6735875-0
KasperskyVirus.Win32.VB.mz
BitDefenderWin32.Gosys.B
NANO-AntivirusTrojan.Win32.Swisyn.flhacn
AvastWin32:VB-OJQ [Wrm]
EmsisoftWin32.Gosys.B (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLP.Swisyn
ZillyaVirus.HLLP.Win32.1
TrendMicroPE_SWISB.A
SophosTroj/Agent-ABZF
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.hxgb
WebrootW32.Malware.Gen
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Agent
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.QOTY@4qfd0g
MicrosoftWorm:Win32/Mofksys!pz
ZoneAlarmVirus.Win32.VB.mz
GDataWin32.Trojan.PSE1.1NLNP9O
GoogleDetected
AhnLab-V3Worm/Win32.Mofksys.R198176
Acronissuspicious
BitDefenderThetaAI:Packer.6157DCDA20
ALYacWin32.Gosys.B
TACHYONWorm/W32.VB-Mofksys.Zen
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Spy.AT
TrendMicro-HouseCallPE_SWISB.A
RisingTrojan.Agent!1.6A70 (CLASSIC)
IkarusWorm.Mofksys
MaxSecureVirus.W32.Agent.xjgj
FortinetW32/VB.QCC!tr.dldr
ZonerTrojan.Win32.88925
DeepInstinctMALICIOUS

How to remove Worm:Win32/Mofksys!pz?

Worm:Win32/Mofksys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment