Worm

Worm:Win32/Wenper removal tips

Malware Removal

The Worm:Win32/Wenper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Wenper virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Wenper?


File Info:

name: CDC111A93E9041D1E63A.mlw
path: /opt/CAPEv2/storage/binaries/1cd08e31d93d92bcbfa1f3be875ce2e911c6216811272fdbc7dfb8c59851fad3
crc32: E79544E1
md5: cdc111a93e9041d1e63aa0a124bec465
sha1: 1f91f9e0d29cd4137f5d2bdf802ec84f234b676c
sha256: 1cd08e31d93d92bcbfa1f3be875ce2e911c6216811272fdbc7dfb8c59851fad3
sha512: 518807d331d8b6216199cf981a14a51c649c6838ae333f2f71239478fde2d8eb408542f3172af270e10e3f8e3f7631c39fb45cc10fb38845e443a24fcbd10db7
ssdeep: 3072:P7ueG9ErYsU+AcI2rv3bo7MnTqtQdhZH4:P7uF9ErUeI2rfdqtQXJ4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16BE3C003BE94C436F0C546F1AD39CA73E57EBA201B62525F97ACD2194EB7160ED0A34B
sha3_384: 7d0f266cfe85265850528f5d7a0c388df600eb7831062c2effedb601fc1054de5ecfc2ba81a67c44d995c12304a7a74d
ep_bytes: eb1066623a432b2b484f4f4b90e960c1
timestamp: 2003-02-16 09:38:52

Version Info:

0: [No Data]

Worm:Win32/Wenper also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Wenper.lVEU
Elasticmalicious (moderate confidence)
MicroWorld-eScanDropped:Generic.Malware.SWg.8AF8FE6E
FireEyeGeneric.mg.cdc111a93e9041d1
SkyhighBehavesLike.Win32.Gbot.cm
McAfeeW32/Wenper.worm.a.gen
MalwarebytesWenper.Worm.Spreader.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaWorm:Win32/Wenper.a006de09
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.VB.d
VirITWorm.Win32.Wenper.A
SymantecW32.Wenper.Worm
ESET-NOD32Win32/Wenper.B
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT_005957.TOMB
ClamAVWin.Malware.Zusy-9654284-0
KasperskyWorm.Win32.Wenper.a
BitDefenderDropped:Generic.Malware.SWg.8AF8FE6E
NANO-AntivirusTrojan.Win32.Wenper.cstcfh
AvastWin32:Wenper-D [Wrm]
TencentTrojan.Win32.Wenper.a
SophosW32/Wenper-A
GoogleDetected
F-SecureWorm.WORM/Wenper.U
DrWebWin32.HLLW.Wencrypt
ZillyaWorm.Wenper.Win32.24
TrendMicroTROJ_AGENT_005957.TOMB
Trapminemalicious.high.ml.score
EmsisoftDropped:Generic.Malware.SWg.8AF8FE6E (B)
IkarusWorm.Win32.Wenper
JiangminWorm.Wenper.p
VaristW32/Wenper.A.gen!Eldorado
AviraWORM/Wenper.U
Antiy-AVLWorm/Win32.Wenper
KingsoftWin32.Worm.Wenper.a
MicrosoftWorm:Win32/Wenper
XcitiumWorm.Win32.Wenper.A@4ldyth
ArcabitGeneric.Malware.SWg.8AF8FE6E
ViRobotWorm.Win32.A.Wenper.96256
ZoneAlarmWorm.Win32.Wenper.a
GDataDropped:Generic.Malware.SWg.8AF8FE6E
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Wenper.R10960
Acronissuspicious
VBA32BScope.Worm.Wenper
ALYacDropped:Generic.Malware.SWg.8AF8FE6E
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Wenper.l (CLASSIC)
YandexTrojan.GenAsa!buUSwtNAaAA
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Wenper.a
FortinetW32/Wenper.A!worm
BitDefenderThetaAI:Packer.58AAFEE21E
AVGWin32:Wenper-D [Wrm]
Cybereasonmalicious.93e904
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Wenper

How to remove Worm:Win32/Wenper?

Worm:Win32/Wenper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment