Worm

Worm:Win32/SillyShareCopy.AU removal tips

Malware Removal

The Worm:Win32/SillyShareCopy.AU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/SillyShareCopy.AU virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities
  • Uses XCOPY for copying files

Related domains:

wpad.local-net
teststaff.ru

How to determine Worm:Win32/SillyShareCopy.AU?


File Info:

name: 444FFC7FE2157A40EDAB.mlw
path: /opt/CAPEv2/storage/binaries/7d2357bd4d29f2ce891bc0f1cebb9ffa965b2c1d91d6f42d11eab4777c1a958d
crc32: 11D41849
md5: 444ffc7fe2157a40edabd13da1c8a416
sha1: 57038bf3d932b6d7d2e6c1f2166ae77438e8bcf6
sha256: 7d2357bd4d29f2ce891bc0f1cebb9ffa965b2c1d91d6f42d11eab4777c1a958d
sha512: e971bcd99c7a85341692af41241d920972f55d8e7b7df1857e1e608ba45fa2998f0e7c6105aa68284714a6543232236f8cef924e497edf7dfe3b4bb1faac6d73
ssdeep: 196608:ADW4UwVIpV5t0fBRs04kwW8di6K6s743gH1Oy4:w9Uwix0fBRkk4cN6s7THt4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16376338A76AAC6D6D2A52DF1C07251F6ACFB3CD0FD812427BE42FDD9B27E5004D502A1
sha3_384: 4396a17f51cca79846c39d2da0aa96e97e883215f759df6b6f13387fe14b86fdada4f2dba7b5c657c7131601fd371226
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

Worm:Win32/SillyShareCopy.AU also known as:

LionicTrojan.NSIS.Agent.4!c
Elasticmalicious (high confidence)
McAfeeArtemis!444FFC7FE215
ZillyaTrojan.Agent.Win32.571207
K7AntiVirusTrojan ( 004cfbc61 )
AlibabaWorm:Win32/Miner.cd23d739
K7GWTrojan ( 004cfbc61 )
Cybereasonmalicious.fe2157
BaiduNSIS.Worm.Agent.a
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/Agent.A
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.NSIS.Agent.gj
NANO-AntivirusTrojan.Nsis.Agent.dyzakg
AvastWin32:PUP-gen [PUP]
TencentTrojan.Win32.BitCoinMiner.la
DrWebTrojan.Siggen6.37779
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DKQ21
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
SophosMal/Generic-R + Mal/Miner-C
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.BSE.W1TQ4E
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwNS.7443
GridinsoftRansom.Win32.Gen.sa
MicrosoftWorm:Win32/SillyShareCopy.AU
CynetMalicious (score: 100)
AhnLab-V3HackTool/Win32.BitCoinMiner.R164217
VBA32Trojan.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0DKQ21
FortinetNSIS/CoinMiner.GJ!tr
AVGWin32:PUP-gen [PUP]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Worm:Win32/SillyShareCopy.AU?

Worm:Win32/SillyShareCopy.AU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment