Worm

How to remove “Worm:Win32/Stercogs.B”?

Malware Removal

The Worm:Win32/Stercogs.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Stercogs.B virus can do?

  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk

How to determine Worm:Win32/Stercogs.B?


File Info:

name: 5CBDD2E2FD9F4F6021FB.mlw
path: /opt/CAPEv2/storage/binaries/f54472e7f6e02875f8278a8187c8a2facd77607f05be00f8ccb88afb2f8f2436
crc32: 0F26EA50
md5: 5cbdd2e2fd9f4f6021fb358123f7c81b
sha1: 73521933f458a83160f67a503970d4c1cdb390f0
sha256: f54472e7f6e02875f8278a8187c8a2facd77607f05be00f8ccb88afb2f8f2436
sha512: 1e5c454a4d06b7f90f9d78cf3dcc22ee0781296374c7ce4526fad6d344c0aab58ce5844b9aa7cb36b1952106e6c3a3353d93ef7a966f0a538760babe46a000c9
ssdeep: 1536:Sdyql1M7wIIEuti7rEYivykYkpaWj0OhG7mJAm/lGb3lls:SdV1Z1i3QKqhGCJr/lh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128939E127AE180B2C48541BC1A9C8F54AB7BBC1455BDD903EB544A8BEFF22D2D73E316
sha3_384: ac5a10cf50df09ea53846bd3ccfbd1b4c0d697cb9f1322b02d54adf46203dfd02ab00189ae76681d9a994ebe80b5b5e4
ep_bytes: 6a606830e34000e8dc0e0000bf940000
timestamp: 2007-08-24 09:13:57

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Support connection to SharePoint Portal Server
FileVersion: 5.1.10
InternalName: sppsvr.exe
LegalCopyright: © Microsoft Corporation. All right reserved.
OriginalFilename: sppsvr.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.10
Translation: 0x0409 0x04b0

Worm:Win32/Stercogs.B also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.30
FireEyeGeneric.mg.5cbdd2e2fd9f4f60
CAT-QuickHealWorm.Stercogs.B4
McAfeeGenericRXFF-JN!5CBDD2E2FD9F
MalwarebytesMalware.AI.100878257
ZillyaTrojan.Agent.Win32.725
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 005327141 )
K7GWEmailWorm ( 005327141 )
Cybereasonmalicious.2fd9f4
VirITTrojan.Win32.Agent.BJI
CyrenW32/NewMalware-Rootkit-I-based!
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Stercogs.A
APEXMalicious
ClamAVWin.Trojan.Agent-182755
KasperskyTrojan.Win32.Agent.aqhn
BitDefenderGen:Heur.Mint.Zard.30
NANO-AntivirusTrojan.Win32.Agent.lyzr
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:Adware-gen [Adw]
TencentTrojan.Win32.Agent.zaa
TACHYONTrojan/W32.Agent.96256.Q
SophosW32/Stercogs-A
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebAdware.Baidu.391
VIPREGen:Heur.Mint.Zard.30
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
EmsisoftGen:Heur.Mint.Zard.30 (B)
IkarusTrojan.Crypt
GDataGen:Heur.Mint.Zard.30
JiangminTrojan/Agent.ckli
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Win32.Agent
ArcabitTrojan.Mint.Zard.30
ViRobotTrojan.Win32.Agent.96256.R
ZoneAlarmTrojan.Win32.Agent.aqhn
MicrosoftWorm:Win32/Stercogs.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R5522
BitDefenderThetaAI:Packer.E15472C01F
MAXmalware (ai score=88)
VBA32Trojan.Agent
Cylanceunsafe
PandaGeneric Malware
RisingTrojan.Win32.Agent.gsm (CLASSIC)
YandexTrojan.GenAsa!eJ/Hvs8WfCY
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.W32.Agent.aqhn
FortinetW32/Agent.GOO!tr.dldr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Stercogs.B?

Worm:Win32/Stercogs.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment