Worm

About “Vercuser.Worm.Spreader.DDS” infection

Malware Removal

The Vercuser.Worm.Spreader.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Vercuser.Worm.Spreader.DDS virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Vercuser.Worm.Spreader.DDS?


File Info:

name: 721B5DCBC17388DF682A.mlw
path: /opt/CAPEv2/storage/binaries/cd45f9f01149415fa08c4abb51cb686402275979b52bffb3b83c46ef553aa17f
crc32: 43C9436E
md5: 721b5dcbc17388df682afc2f36fbffb1
sha1: f3f3874a3fcde015fb07c9747002778b75b006fa
sha256: cd45f9f01149415fa08c4abb51cb686402275979b52bffb3b83c46ef553aa17f
sha512: 780d26ca712ec3d2e6043348303205c2b478127196623a99caaff1ca9c73d92295014525f59019284062f2d8b366f7d8b9ea6d0ffa155f9986bc37cd3cda1e01
ssdeep: 24576:ecYgrl5t6PDGdnQJlzUYUJiYTV5Fak7KFRm7Kz:JAz/Us6R7KW7Kz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F525C016F18640F3D681307054BABA235A3EB16E97F899D3B7E42D66BC051C2B87538F
sha3_384: 98ec63d493ceb8ddb96ff91ae59d96bde48f04caaba80e3aca835df6f3b1901e01822dccc86c79cf6ba3bd2b4f946023
ep_bytes: 8bec609ce9f58c0400ff8bff558bec51
timestamp: 2003-03-02 06:35:07

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Explorer
FileVersion: 8.1.5353.17671 (win7sp1_rtm.101119-1850)
InternalName: explorer
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: EXPLORER.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 8.1.5353.17671
Translation: 0x0409 0x04b0

Vercuser.Worm.Spreader.DDS also known as:

BkavW32.AIDetect.malware1
AVGWin32:AutoRun-DAS [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanMemScan:Worm.Generic.390906
ALYacMemScan:Worm.Generic.390906
CylanceUnsafe
VIPREMemScan:Worm.Generic.390906
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.bc1738
BaiduWin32.Worm.Agent.ig
VirITTrojan.Win32.X-Fiha.NT
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Tinba-9943147-2
KasperskyWorm.Win32.AutoHotKey.a
BitDefenderMemScan:Worm.Generic.390906
AvastWin32:AutoRun-DAS [Trj]
Ad-AwareMemScan:Worm.Generic.390906
EmsisoftMemScan:Worm.Generic.390906 (B)
ComodoWorm.Win32.Vercuser.B@4tvs04
DrWebWin32.HLLW.Autoruner3.6520
TrendMicroTROJ_AGENT_057923.TOMB
McAfee-GW-EditionW32/Worm-FLM!721B5DCBC173
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.721b5dcbc17388df
SophosGeneric ML PUA (PUA)
IkarusWorm.Win32.Vercuser
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitWorm.Generic.D5F6FA
ZoneAlarmWorm.Win32.AutoHotKey.a
GDataMemScan:Worm.Generic.390906
GoogleDetected
Acronissuspicious
McAfeeW32/Worm-FLM!721B5DCBC173
MAXmalware (ai score=82)
VBA32Heur.Trojan.Hlux
MalwarebytesVercuser.Worm.Spreader.DDS
TrendMicro-HouseCallTROJ_AGENT_057923.TOMB
RisingWorm.Win32.Vercuser.b (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FakeAV.HOSP!tr
BitDefenderThetaAI:Packer.708FCC2220
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Vercuser.Worm.Spreader.DDS?

Vercuser.Worm.Spreader.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment