Worm

Worm.Wace malicious file

Malware Removal

The Worm.Wace is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Wace virus can do?

  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.Wace?


File Info:

name: 54D7D46120CBAC924475.mlw
path: /opt/CAPEv2/storage/binaries/329cc2a7fe9eaf563ec1c5689142c6144fa2ebc8ec4328b0edfb789106e1bf35
crc32: 3D30C173
md5: 54d7d46120cbac92447581bd238da1ce
sha1: b876c2d3c37171490d6d4f6721630f825c06b620
sha256: 329cc2a7fe9eaf563ec1c5689142c6144fa2ebc8ec4328b0edfb789106e1bf35
sha512: 1fceab54ecf149540ea2047990b04a7d2d83e8b393ad0b758927a6453a7c78f3a42546e8ce243e218aeed923b9088c793528b66e0963831d9fa82abd051e38fb
ssdeep: 3072:0dD9TfWGYmIW8WPvAL+YeCf8ZB/lGmXqyx:0dD9bWCWW3UNerDX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188A302E8CA442E8EE9958630E2CACD4E00DF581953D37F3E49A81F18373E5D667D0466
sha3_384: 407cef36d2e2a32e43553a7a0a3e87257664b2636e3a835a474fbba53bda406be091ba026495e59c3d5c3853a68b1780
ep_bytes: 60be000042008dbe0010feff5783cdff
timestamp: 2006-11-09 01:52:26

Version Info:

Comments:
CompanyName: 北京江民新科技术有限公司
FileDescription: “威金”蠕虫专杀工具
FileVersion: 2, 0, 0, 0
InternalName: VikingKiller
LegalCopyright: 江民公司 版权所有 (C) 2006
LegalTrademarks:
OriginalFilename: VikingKiller.EXE
PrivateBuild:
ProductName: “威金”蠕虫专杀工具
ProductVersion: 2, 0, 0, 0
SpecialBuild:
Translation: 0x0804 0x04b0

Worm.Wace also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.54d7d46120cbac92
SangforTrojan.Win32.Agent.Vioi
CrowdStrikewin/malicious_confidence_60% (W)
Elasticmalicious (moderate confidence)
APEXMalicious
Paloaltogeneric.ml
AvastWin32:Malware-gen
F-SecureHeuristic.HEUR/AGEN.1346630
McAfee-GW-EditionRDN/Generic.dx
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.Agent.ACEJ5U
AviraHEUR/AGEN.1346630
Antiy-AVLTrojan/Win32.Sabsik
CynetMalicious (score: 100)
McAfeeRDN/Generic.dx
VBA32Worm.Wace
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH06DK23
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.3c3717
DeepInstinctMALICIOUS

How to remove Worm.Wace?

Worm.Wace removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment