Worm:Win32/Sfone removal tips

Malware Removal

The Worm:Win32/Sfone is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Worm:Win32/Sfone virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.bing.com
crl3.digicert.com
ocsp.digicert.com

How to determine Worm:Win32/Sfone?


File Info:

crc32: BC2DFCF0
md5: a08b33314cebf70fe2643017b7bb6409
name: A08B33314CEBF70FE2643017B7BB6409.mlw
sha1: 8a5df9c9e8d9f983929eec23a7f8e8adf365422e
sha256: 44e20f5855724b26d41e788abd3e4a2212ae485ad7f5bef446ba1114dbfb6564
sha512: 8d77ba5d8b68c9d566cacbeafadbbf57ac3ea143215cde946a0589e4690abaece0c864346df739846ebd23723db162ea523d65afe009e407af4b3b74ba304c25
ssdeep: 6144:CjluQoSIIo5R1Nl090To7oDvY1EBCrML+FlHxMP7S+FhuD:CEQoSs5Ni90TNdCrM4HuznzM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Sfone also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70387
FireEyeGeneric.mg.a08b33314cebf70f
McAfeeGenericRXKN-BX!A08B33314CEB
CylanceUnsafe
VIPREWorm.Win32.Agent.cp (v)
SangforMalware
K7AntiVirusTrojan ( 0051918e1 )
BitDefenderTrojan.GenericKDZ.70387
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.14cebf
InvinceaML/PE-A + Troj/Agent-BFWE
BitDefenderThetaAI:Packer.19C454781E
CyrenW32/Agent.BTR.gen!Eldorado
SymantecW32.SillyWNSE
APEXMalicious
AvastWin32:WormX-gen [Wrm]
ClamAVWin.Worm.SillyWNSE-7784290-0
KasperskyWorm.Win32.Agent.cp
NANO-AntivirusTrojan.Win32.Wofith.hzygna
TencentMalware.Win32.Gencirc.10ba4358
Ad-AwareTrojan.GenericKDZ.70387
SophosTroj/Agent-BFWE
ComodoWorm.Win32.Agent.CP@42tt
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop15.57947
ZillyaWorm.Agent.Win32.52973
TrendMicroWorm.Win32.SFONE.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftTrojan.GenericKDZ.70387 (B)
IkarusWorm.Win32.Agent
JiangminWorm.Agent.ws
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.Agent.cp
MicrosoftWorm:Win32/Sfone
GridinsoftTrojan.Heur!.030120A9
ArcabitTrojan.Generic.D112F3
ZoneAlarmWorm.Win32.Agent.cp
GDataTrojan.GenericKDZ.70387
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Agent.R336858
Acronissuspicious
VBA32Worm.Agent
ALYacTrojan.GenericKDZ.70387
MAXmalware (ai score=89)
MalwarebytesTrojan.Agent.Generic
PandaGeneric Suspicious
ESET-NOD32a variant of Win32/Agent.CP
TrendMicro-HouseCallWorm.Win32.SFONE.SM
RisingWorm.Agent!1.BDD2 (TFE:1:EV1tbXRZcAI)
YandexWorm.Agent!LBOC44jF1A4
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.6C6A!tr
AVGWin32:WormX-gen [Wrm]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM18.1.1DFB.Malware.Gen

How to remove Worm:Win32/Sfone?

Worm:Win32/Sfone removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment