Worm

Should I remove “Worm:MSIL/Wisbipuf.C”?

Malware Removal

The Worm:MSIL/Wisbipuf.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:MSIL/Wisbipuf.C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Deletes executed files from disk
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Worm:MSIL/Wisbipuf.C?


File Info:

name: ABB53EDFA5DD5550B009.mlw
path: /opt/CAPEv2/storage/binaries/8be8808efaf5e099c980492e738b04f3c1595bd29a5090575621a53e80fec033
crc32: D7018576
md5: abb53edfa5dd5550b009f7eceba0552b
sha1: 0839d16da1ecb0eb139943037a02b194f3f27fbb
sha256: 8be8808efaf5e099c980492e738b04f3c1595bd29a5090575621a53e80fec033
sha512: 02ddaacbc32ffc6dbc8edbb4e8a8c90f2381773c39b3068306fa7d8f2410d0cee3c4a450dc32caf3c4e2f97be76538d5bd877d30f090c17b8c4393c25d64157e
ssdeep: 12288:v39D+AzekXSxWQOfx3MZts81l5h6MDdJ3F2:lKM/Q0x3ytLNh6MnF2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171B4BE1752DD6EA2C4BC16717732C3E1C338EE025653D66D68C8689BBA7B38339027D5
sha3_384: 49acf789ab082492e3c80fa255ade6bd756ab350c16555e21997eda652209c78d71e7208f7abe53e9ee5c5ccd0ac854d
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-12-25 12:23:25

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 4.2.4.6
InternalName: i.exe
LegalCopyright: Copyright
OriginalFilename: i.exe
ProductVersion: 4.2.4.6
Assembly Version: 4.1.7.8

Worm:MSIL/Wisbipuf.C also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Ser.MSILPerseus.5011
FireEyeGeneric.mg.abb53edfa5dd5550
ALYacGen:Variant.Ser.MSILPerseus.5011
CylanceUnsafe
VIPREGen:Variant.Ser.MSILPerseus.5011
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_60% (D)
BaiduMSIL.Worm.Agent.b
VirITTrojan.Win32.MSIL6.SQY
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.JD
APEXMalicious
ClamAVWin.Trojan.Agent-1323488
KasperskyTrojan.MSIL.Agent.aaffa
BitDefenderGen:Variant.Ser.MSILPerseus.5011
AvastMSIL:Bladabindi-CK [Trj]
TencentMsil.Trojan.Agent.Lpuz
Ad-AwareGen:Variant.Ser.MSILPerseus.5011
EmsisoftGen:Variant.Ser.MSILPerseus.5011 (B)
DrWebTrojan.MulDrop5.45487
TrendMicroWorm.MSIL.WISBIPUF.SM
McAfee-GW-EditionGenericRXES-RT!ABB53EDFA5DD
SophosML/PE-A
IkarusBackdoor.MSIL.Bladabindi
GDataGen:Variant.Ser.MSILPerseus.5011
JiangminTrojan.MSIL.ofqt
AviraTR/Special.30720
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.3
ArcabitTrojan.Ser.MSILPerseus.D1393
MicrosoftWorm:MSIL/Wisbipuf.C
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Bladabindi.R131405
McAfeeGenericRXES-RT!ABB53EDFA5DD
TACHYONTrojan/W32.DN-Agent.530944.I
VBA32Trojan.MSIL.Agent
MalwarebytesWorm.Agent.MSIL
TrendMicro-HouseCallWorm.MSIL.WISBIPUF.SM
RisingTrojan.Wisbipuf!1.AEA5 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.6286590.susgen
FortinetMSIL/Agent.JD!tr
BitDefenderThetaGen:NN.ZemsilF.34806.Gm0@aGpUG8o
AVGMSIL:Bladabindi-CK [Trj]
Cybereasonmalicious.fa5dd5

How to remove Worm:MSIL/Wisbipuf.C?

Worm:MSIL/Wisbipuf.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment