Worm

How to remove “Worm.Win32.RussoTuristo.du”?

Malware Removal

The Worm.Win32.RussoTuristo.du is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.RussoTuristo.du virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Worm.Win32.RussoTuristo.du?


File Info:

name: DC14720AD682454E4FFE.mlw
path: /opt/CAPEv2/storage/binaries/b0391c4575f07e11d059451a42b6460cc4353138b963b511f0f319e798d01119
crc32: FCD781B9
md5: dc14720ad682454e4ffe90d40a092126
sha1: 782a7948105edb1646a5449ed2278625309857ba
sha256: b0391c4575f07e11d059451a42b6460cc4353138b963b511f0f319e798d01119
sha512: cef4d748f162a75f5ebfb7befc7bb5e9d69fc99678ae7be88dfca16902b9bca20d2623daa491a4bdc1f9369c0c3a19043286841d5949bc5a47ca670b63c5147f
ssdeep: 768:PDnQNDnQ6CG2k+/8W8SmbXwqAFy6+37fp84lGYSwvTwUVVAtI6EQzTGf3gNH:LnynVnT+Y9zwqJ6cf21Qyq6EQMg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB149E8BA703C61AE824C87A85035618A784FE629E1B3E7391117E7B3D370D9DF27572
sha3_384: 6ad306c802e1f9e061ecaafa2639dea0fcb2121cff07ecdff0ae4f12773d8838ef089477ba63a6f23bf209c52ce7939e
ep_bytes: 00000000000000000000000000000000
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.Win32.RussoTuristo.du also known as:

Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.dc14720ad682454e
McAfeeNew Malware.al
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BaiduWin32.Worm.Agent.hx
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.RussoTuristo.du
AvastWin32:Agent-AVDA [Trj]
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebWin32.HLLW.Amorale
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
Trapminemalicious.moderate.ml.score
AviraTR/Crypt.XPACK.Gen
Antiy-AVLWorm/Win32.RussoTuristo
ZoneAlarmWorm.Win32.RussoTuristo.du
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32Worm.RussoTuristo
MalwarebytesGeneric.Trojan.Downloader.DDS
SentinelOneStatic AI – Malicious PE
AVGWin32:Agent-AVDA [Trj]

How to remove Worm.Win32.RussoTuristo.du?

Worm.Win32.RussoTuristo.du removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment