Worm

About “Worm:MSIL/Sipia.A” infection

Malware Removal

The Worm:MSIL/Sipia.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:MSIL/Sipia.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Worm:MSIL/Sipia.A?


File Info:

crc32: F142A1FA
md5: e3bc89b0b02ee4e933d73cb5a012e0c8
name: E3BC89B0B02EE4E933D73CB5A012E0C8.mlw
sha1: 24543700feea9dea3926110da67b3ba671b405d8
sha256: 1a1b94b3853a2f8678516d0937a7029056d1acbc4b73968ae1e823191cf37a7f
sha512: 1ed49651235b1b3f0e2bcce9bde8e87668aed1e2c1a858640cea09ef0758fdcbd08a669423ec73d2f038b48cdbb4f604b85dec7f25c21b75325c525be5bcc8e2
ssdeep: 3072:ktOoOtxCnHoMJt3gMEf5UgIxbFqk/VUAibnNT+9d6bgTakxQm:ktt3gMEfDIx8k/VUP+4k
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: taskmgr.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: taskmgr.exe

Worm:MSIL/Sipia.A also known as:

K7AntiVirusTrojan ( 0056fe471 )
LionicTrojan.Win32.Generic.m3RH
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop5.34489
CynetMalicious (score: 99)
ALYacGen:Heur.MSIL.Androm.9
CylanceUnsafe
ZillyaTrojan.Generic.Win32.49375
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:MSIL/Sipia.917b9858
K7GWTrojan ( 0056fe471 )
Cybereasonmalicious.0b02ee
CyrenW32/Agent.AQM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.D
APEXMalicious
AvastMSIL:GenMalicious-AH [Trj]
ClamAVWin.Packed.Gamarue-6913056-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Heur.MSIL.Androm.9
NANO-AntivirusTrojan.Win32.RiskGen.ddrguz
MicroWorld-eScanGen:Heur.MSIL.Androm.9
TencentMsil.Worm.Injector.Akoy
Ad-AwareGen:Heur.MSIL.Androm.9
SophosMal/Generic-R + Mal/MsilDyn-E
ComodoTrojWare.MSIL.Injector.OY@5nrgi5
BitDefenderThetaGen:NN.ZemsilF.34236.Jm0@aWBNfYl
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.ht
FireEyeGeneric.mg.e3bc89b0b02ee4e9
EmsisoftGen:Heur.MSIL.Androm.9 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.MSIL.fec
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.139FB1D
MicrosoftWorm:MSIL/Sipia.A
ArcabitTrojan.MSIL.Androm.9
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Heur.MSIL.Androm.9
AhnLab-V3Trojan/Win32.Bladabindi.C2405018
McAfeeGenericRXAS-XX!E3BC89B0B02E
MAXmalware (ai score=99)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.AutoRun
PandaTrj/CI.A
YandexWorm.Injector!wUlRP7XtoFM
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.D!worm
AVGMSIL:GenMalicious-AH [Trj]
Paloaltogeneric.ml

How to remove Worm:MSIL/Sipia.A?

Worm:MSIL/Sipia.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment