Worm

How to remove “Worm:Win32/Sfone.A”?

Malware Removal

The Worm:Win32/Sfone.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Sfone.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • A possible heap spray exploit has been detected
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Harvests cookies for information gathering

How to determine Worm:Win32/Sfone.A?


File Info:

name: 2688BD480BD80BA68D20.mlw
path: /opt/CAPEv2/storage/binaries/5c1746eb58e20f16ee6c5b1476bba4c9e435b57eef8c0147d10ccafbe2031ea4
crc32: 48B575A5
md5: 2688bd480bd80ba68d208cb7b3184dd9
sha1: 62ceb62ab16e43ff43eeb3215e82228f05a99ff1
sha256: 5c1746eb58e20f16ee6c5b1476bba4c9e435b57eef8c0147d10ccafbe2031ea4
sha512: 11358787e77676310ccaa74210efb1600cb4dff4f0220670ef03b61896a81cbf1d3ee232f6b4dfdc99b9ca349712a16f4aeb0c3cece85e9fbbebdf9ecb555b5a
ssdeep: 1536:A3jWj+DOd5AJyWt0icToSHCMmvLsrny/pwFquLFUTQnN3R9M5WLiVwt31b6K1J3:ATLoAJytFCMmDR/pqqsFUCN3R9MI+Q3z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11093BFC03D85C43ED01A513A5A89B53A5C78D6352521CEC7EFD0FA59AF8D2B0A62C7B3
sha3_384: 1490e42c90fd296295dd24e03548eed4479b9e696e7d5de267d8786ee33ea91a8e5afab50b3e21035c47260c05e2f598
ep_bytes: 5589e56aff68dc18410068d85d400064
timestamp: 2006-03-02 17:50:37

Version Info:

0: [No Data]

Worm:Win32/Sfone.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.SPfVoPk!1!prn!.FE0B916D
FireEyeGeneric.mg.2688bd480bd80ba6
CAT-QuickHealWorm.Sfone.A3
ALYacGeneric.Malware.SPfVoPk!1!prn!.FE0B916D
CylanceUnsafe
ZillyaWorm.Agent.Win32.9
K7AntiVirusEmailWorm ( 00571eb41 )
K7GWEmailWorm ( 00571eb41 )
Cybereasonmalicious.80bd80
BitDefenderThetaAI:Packer.A4AAEA4E1E
CyrenW32/Worm.KOKR-0749
SymantecW32.SillyWNSE
ESET-NOD32a variant of Win32/Agent.CP
ClamAVWin.Malware.Sfone-6763601-0
KasperskyHEUR:Trojan.Win32.Wofith.vho
BitDefenderGeneric.Malware.SPfVoPk!1!prn!.FE0B916D
NANO-AntivirusTrojan.Win32.Wofith.iariji
AvastWin32:Agent-URR [Trj]
TencentWorm.Win32.Agent.d
Ad-AwareGeneric.Malware.SPfVoPk!1!prn!.FE0B916D
SophosML/PE-A + Troj/Agent-BFWE
BaiduWin32.Worm.Agent.fj
DrWebWin32.HLLW.Siggen.1607
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nh
EmsisoftGeneric.Malware.SPfVoPk!1!prn!.FE0B916D (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Sfone.B
JiangminWorm.Agent.yh
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASCommon.1C4
MicrosoftWorm:Win32/Sfone.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Agent.R233959
Acronissuspicious
McAfeeW32/Generic.worm.f
MAXmalware (ai score=88)
VBA32BScope.Worm.Agent
MalwarebytesWorm.Sform
APEXMalicious
RisingWorm.Agent!1.CEBD (CLASSIC)
YandexTrojan.GenAsa!2oUtO9JdH+o
IkarusWorm.Win32.Agent
MaxSecurePoly.Worm.Agent.CP
FortinetW32/Agent.CP!worm
AVGWin32:Agent-URR [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Sfone.A?

Worm:Win32/Sfone.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment