Categories: Worm

Worm:Win32/Wukill.BS removal

The Worm:Win32/Wukill.BS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Wukill.BS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Wukill.BS?


File Info:

crc32: 092C3376md5: 0d116a5cd87f96d96703ce55bf091f57name: 0D116A5CD87F96D96703CE55BF091F57.mlwsha1: 835aa2dc7654ca1200315ef8688f485c98cc8e1csha256: ffc81839c0a792be103ee9b3c93972850289ecdf48b2b46f1d42a064ff97555esha512: 2950b28b9c8a9b44d14c6cac597e8d6e63c62f1dff3dfd3e1f989a6c1568e0e5809e67b61a4d696d05180e71b531668c88acf0d9ce47e544f28ea1266ab5dbaassdeep: 3072:Pg8QhLnvUaFPmgRMNlPTGQQm6ytwZEsrYkK4:PxQhD98gWNlPTGQQm6agrdtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0InternalName: EXPLORERFileVersion: 1.00CompanyName: gyProductName: XgtrayProductVersion: 1.00OriginalFilename: EXPLORER.exe

Worm:Win32/Wukill.BS also known as:

Bkav W32.Tempicom.Worm
K7AntiVirus Trojan ( 004e6d9a1 )
DrWeb Win32.HLLM.Utenti
MicroWorld-eScan GenPack:Trojan.Agent.VB.BFY
CMC Generic.Win32.0d116a5cd8!MD
ALYac GenPack:Trojan.Agent.VB.BFY
Cylance Unsafe
Zillya Worm.Wukill.Win32.4
Sangfor Malware
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Worm:Win32/Wukill.7d723cab
K7GW Trojan ( 004e6d9a1 )
Cybereason malicious.cd87f9
TrendMicro WORM_TRAXG.C
ESET-NOD32 Win32/Wukill.J
APEX Malicious
TotalDefense Win32/Traxg.P
Avast Win32:Rootkit-gen [Rtk]
ClamAV Win.Worm.Silly-62
GData GenPack:Trojan.Agent.VB.BFY
Kaspersky Email-Worm.Win32.Wukill.m
BitDefender GenPack:Trojan.Agent.VB.BFY
NANO-Antivirus Trojan.Win32.Silly.ghtx
ViRobot I-Worm.Win32.Silly.154624
SUPERAntiSpyware Trojan.TempCom
Tencent Trojan.Win32.FakeFolder.wid
Ad-Aware GenPack:Trojan.Agent.VB.BFY
Sophos W32/Traxg-B
Comodo Worm.Win32.Wukill.J@upx
F-Secure Worm.WORM/Silly.K
BitDefenderTheta AI:Packer.BE58AE821D
VIPRE Email-Worm.Win32.Xgtray.gen (v)
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.Generic.cc
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.0d116a5cd87f96d9
Emsisoft GenPack:Trojan.Agent.VB.BFY (B)
SentinelOne DFI – Suspicious PE
Endgame malicious (high confidence)
Webroot Worm:Win32/Wukill
Avira WORM/Silly.K
eGambit Unsafe.AI_Score_100%
Antiy-AVL Worm[Email]/Win32.Silly
Microsoft Worm:Win32/Wukill.BS
Jiangmin I-Worm.Silly.b
Arcabit GenPack:Trojan.Agent.VB.BFY
AegisLab Trojan.Win32.Generic.leu8
ZoneAlarm Email-Worm.Win32.Wukill.m
TACHYON Worm/W32.Silly.154624
AhnLab-V3 Worm/Win32.Traxg.R2565
Acronis suspicious
McAfee W32/Generic.l
MAX malware (ai score=100)
VBA32 SScope.Trojan.VBO.0362
Malwarebytes Worm.Email.Generic
Panda W32/Traxg.C.worm
TrendMicro-HouseCall WORM_TRAXG.C
Rising Trojan.Win32.Nodef.klq (CLOUD)
Yandex I-Worm.Silly!CbgRkRuolCo
Ikarus Virus.Win32.VBInject
MaxSecure Trojan.Malware.1371555.susgen
Fortinet W32/Traxg.B@mm
AVG Win32:Rootkit-gen [Rtk]
Paloalto generic.ml
Qihoo-360 Malware.Radar01.Gen

How to remove Worm:Win32/Wukill.BS?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Malware.AI.4183435755 information

The Malware.AI.4183435755 is considered dangerous by lots of security experts. When this infection is active,…

39 mins ago

Dropped:Application.Generic.3571726 removal instruction

The Dropped:Application.Generic.3571726 is considered dangerous by lots of security experts. When this infection is active,…

44 mins ago

What is “Trojan.Generic.35245150”?

The Trojan.Generic.35245150 is considered dangerous by lots of security experts. When this infection is active,…

50 mins ago

Malware.AI.1658877817 removal tips

The Malware.AI.1658877817 is considered dangerous by lots of security experts. When this infection is active,…

54 mins ago

About “Win32/Pronny.JI” infection

The Win32/Pronny.JI is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Adware.Ursu.14752 removal

The Adware.Ursu.14752 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago