Malware

About “FileRepMalware [Wrm]” infection

Malware Removal

The FileRepMalware [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FileRepMalware [Wrm] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Expresses interest in specific running processes
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Attempts to disable or modify Explorer Folder Options
  • Attempts to disable System Restore
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine FileRepMalware [Wrm]?


File Info:

name: 3B97C1CFB4FDC3FDBCAC.mlw
path: /opt/CAPEv2/storage/binaries/2473c27974b33f92fb43e3d7c9d5896a42a9fd72cf8266acd09d9bc65e4589ed
crc32: CE392D70
md5: 3b97c1cfb4fdc3fdbcacd606674e8f56
sha1: 2d3a5a815294460f468842c129e73d627589029d
sha256: 2473c27974b33f92fb43e3d7c9d5896a42a9fd72cf8266acd09d9bc65e4589ed
sha512: 0ce1bdfd6e0776b7c22e212563e37885a4fb61c9d80e1cd462b2f4d616fbcd3af28f615aa39f2973311557843cd02a8cdefc9708df47db180cb0a059c6efd98e
ssdeep: 3072:Ax/5F/E7tEf0n+p+tYlpJH7iXQNgggHlxDZiYLK5Wph:AxhF4cy+wWJH7igNgjdFKs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0F3C56D3390E33AE21585F83A219268549EFC3405DA8C1FEBC36B167AA5DD3E630753
sha3_384: 2c174a1ea46d035e655f84ec205aceebe139cf21ce59b06af59f8696994921a79066e19bad3bae5364b5becb9804c46a
ep_bytes: 68a8444000e8eeffffff000000000000
timestamp: 2006-11-27 09:24:01

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Oncom
ProductName: xk
FileVersion: 0.00.0020
ProductVersion: 0.00.0020
InternalName: DATA
OriginalFilename: DATA.exe

FileRepMalware [Wrm] also known as:

BkavW32.FamVT.RegVdb.Trojan
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.VB.OJW
FireEyeGeneric.mg.3b97c1cfb4fdc3fd
CAT-QuickHealWorm.Ludbaruma.A3
ALYacTrojan.VB.OJW
CylanceUnsafe
SangforRansom.Win32.Foreign_11.se
K7AntiVirusTrojan ( 0040f6141 )
K7GWP2PWorm ( 0050fa4b1 )
Cybereasonmalicious.fb4fdc
BitDefenderThetaAI:Packer.80EEED3E1D
VirITTrojan.Win32.DownLoader7.FNM
CyrenW32/S-2ee348b2!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.ORD
BaiduWin32.Worm.VB.k
TrendMicro-HouseCallTSPY_LUDBARUMA_BK083EDB.TOMC
ClamAVWin.Trojan.VBGeneric-6735888-0
KasperskyTrojan-Ransom.Win32.Blocker.mtgn
BitDefenderTrojan.VB.OJW
NANO-AntivirusTrojan.Win32.Regrun.dxtouo
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor
APEXMalicious
TencentTrojan.Win32.Blocker.wd
Ad-AwareTrojan.VB.OJW
EmsisoftTrojan.VB.OJW (B)
ComodoTrojWare.Win32.Injector.FZZA@57zyc0
DrWebTrojan.DownLoader7.3730
ZillyaTrojan.RegrunGen.Win32.1
TrendMicroTSPY_LUDBARUMA_BK083EDB.TOMC
McAfee-GW-EditionBehavesLike.Win32.Rontokbro.cm
SophosML/PE-A + W32/Mato-N
IkarusTrojan.AgentMB.VB
GDataWin32.Worm.Ludbaruma.A
JiangminTrojan.Blocker.tav
AviraTR/Agent.gdnw
MAXmalware (ai score=86)
ViRobotWorm.Win32.Regrun.Gen.A
ZoneAlarmTrojan-Ransom.Win32.Blocker.kpuo
MicrosoftWorm:Win32/Ludbaruma.A
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.IRCBot.R1456
McAfeeW32/Rontokbro.gen@MM
TACHYONTrojan/W32.VB-Ludbaruma.Zen.B
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Trojan.Malicious.DDS
AvastFileRepMalware [Wrm]
RisingTrojan.VB!1.BDC8 (KTSE)
YandexTrojan.GenAsa!3Dzo+yWZn14
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan-Ransom.Win32.Blocker.kpuo
FortinetW32/Regrun.PKE!tr
AVGFileRepMalware [Wrm]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove FileRepMalware [Wrm]?

FileRepMalware [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment