Worm

Worm.MSIL.Gibus removal instruction

Malware Removal

The Worm.MSIL.Gibus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.MSIL.Gibus virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Worm.MSIL.Gibus?


File Info:

name: B68191EEBD3C5B3D7EAB.mlw
path: /opt/CAPEv2/storage/binaries/92b1cbf859b2dc77887aa64a1925c8784d439b832f5a50760396704d67e85130
crc32: 3B9656F3
md5: b68191eebd3c5b3d7eabf1048c07e332
sha1: 9961436cf5970e5c9244a53dc8d72066db7c83c6
sha256: 92b1cbf859b2dc77887aa64a1925c8784d439b832f5a50760396704d67e85130
sha512: d5661203f2df030271e1435fe928dd23bd426ed3419b1f45ba4d9a97844b359d74f08db159b8f6029af198ac2dbb8aab8e9815625a305bfa0b3190601c515017
ssdeep: 1536:BgU98rsDKZ75syCAUwZCzXbvcqZJ801bNJJTLo:GU98rsDKZ75syyvpFbNJJ4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D043398C7BE85925C1BE4A774C75A0110779B9438E23CB0F5EE294593A733D1CE89BB2
sha3_384: 2fed6b1dba3ef6c9476db4e14b4ee405f4fd6ecc797ae93639baeb4eac3c7210573ee2678b4c8cd16e844618065737cc
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-04-20 06:31:16

Version Info:

0: [No Data]

Worm.MSIL.Gibus also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.124151
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.MSILPerseus.124151
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.MSILPerseus.124151
K7GWTrojan ( 700000121 )
Cybereasonmalicious.ebd3c5
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Agent.VY
APEXMalicious
ClamAVWin.Packed.Msilperseus-9882424-0
KasperskyHEUR:Worm.MSIL.Gibus.gen
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
Ad-AwareGen:Variant.MSILPerseus.124151
SophosML/PE-A
DrWebBackDoor.Bladabindi.1702
McAfee-GW-EditionBehavesLike.Win32.Backdoor.qm
FireEyeGeneric.mg.b68191eebd3c5b3d
EmsisoftGen:Variant.MSILPerseus.124151 (B)
IkarusTrojan.ILCrypt
GDataGen:Variant.MSILPerseus.124151
JiangminTrojan.Generic.gsxxl
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
ArcabitTrojan.MSILPerseus.D1E4F7
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C4320232
Acronissuspicious
McAfeeGenericRXPS-OF!B68191EEBD3C
MalwarebytesTrojan.Crypt.MSIL
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.YW!tr
BitDefenderThetaGen:NN.ZemsilF.34638.dmW@a4VdTQn
AVGMSIL:Downloader-LX [Trj]
AvastMSIL:Downloader-LX [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.MSIL.Gibus?

Worm.MSIL.Gibus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment