Worm

Worm:Win32/Taterf.D removal tips

Malware Removal

The Worm:Win32/Taterf.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Taterf.D virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Worm:Win32/Taterf.D?


File Info:

crc32: 21F972CA
md5: 45d5ec539a819d4642dfb4894fcf0e61
name: 45D5EC539A819D4642DFB4894FCF0E61.mlw
sha1: 5ae5776ea9ffad8dbb60b3a6c3148a6014883311
sha256: c9f3fbc3be7020566ad19143869e83a7a222a518f87c4a6a330d7162086b97dd
sha512: a41463003e441123e2e8fa0a3c1dd577ed7cfe9a4025475c3322575856da332cd112b1ae8071ace3d1e59353b1b2156f69f5b4577185f5d0f1c186a9d7dcaa57
ssdeep: 3072:dTiWyEq0+GFj1BS+NYwW+p2WcDTwrz/0bakQl4oD9lVM5P:du9mj1BS+NYrOz2s/mal4oD9KP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Taterf.D also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.59782
CynetMalicious (score: 100)
ALYacGen:Variant.Taterf.20
CylanceUnsafe
ZillyaTrojan.Vaklik.Win32.3171
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaWorm:Win32/Taterf.72c3f410
Cybereasonmalicious.39a819
CyrenW32/OnlineGames.FW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.OnLineGames.OUM
APEXMalicious
AvastWin32:FrePack [Cryp]
ClamAVWin.Trojan.OnlineGames-4656
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Taterf.20
NANO-AntivirusTrojan.Win32.Vaklik.ezgup
MicroWorld-eScanGen:Variant.Taterf.20
Ad-AwareGen:Variant.Taterf.20
SophosML/PE-A + Mal/Taterf-E
ComodoMalware@#2oqc5xa62mv89
BitDefenderThetaGen:NN.ZexaF.34088.myWbaupbV@
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DHJ21
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
FireEyeGeneric.mg.45d5ec539a819d46
EmsisoftGen:Variant.Taterf.20 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Vaklik.dnu
WebrootW32.Cycbot.Gen
AviraTR/Crypt.ASPM.Gen2
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.C3C564
KingsoftWin32.Troj.DeepScan.(kcloud)
MicrosoftWorm:Win32/Taterf.D
GDataGen:Variant.Taterf.20
AhnLab-V3Dropper/Win32.OnlineGameHack.R3492
McAfeeArtemis!45D5EC539A81
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0DHJ21
TencentWin32.Trojan.Vaklik.balp
YandexTrojan.PWS.OnLineGames!GMBLr5bmw6Y
IkarusTrojan-GameThief.Win32.Magania
MaxSecureTrojan.Malware.2387168.susgen
FortinetW32/Onlinegames.RA!tr
AVGWin32:FrePack [Cryp]
Paloaltogeneric.ml

How to remove Worm:Win32/Taterf.D?

Worm:Win32/Taterf.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment