Categories: Virus

Virus:Win95/Zofo.2784 removal

The Virus:Win95/Zofo.2784 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win95/Zofo.2784 virus can do?

  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Virus:Win95/Zofo.2784?


File Info:

crc32: B634C259md5: 8e8bcfb370be6edb884ce390be2b945dname: PBRUSH.EXsha1: 4ab39f19c9d1b3c020f47f02d59feea26582041bsha256: d9abcede8949f1c2bbe90ea89ba95b56897584beeb695d0108fb21bc07dc6793sha512: 38ad41b8dfafaea6f8e3686d4f3c7fbb600a2d32e0895b9986b7fac59aa73fe1a1d1cdce9ddb6eb5db84d0bf54981cffc6d9f9889d9a03bc4ec2d37d5ded2726ssdeep: 768:HeoU2H4jk4HgW6DV63UvKLXOqAyqCP4Vv/OzF3Wrnzp:jU2r4HgW6CUvKLXF+HOpmrzptype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 x41ax43ex440x43fx43ex440x430x446x438x44f Microsoft, 1991-1998InternalName: PbrushFileVersion: 4.10.1998CompanyName: x41ax43ex440x43fx43ex440x430x446x438x44f MicrosoftProductName: x41ex43fx435x440x430x446x438x43ex43dx43dx430x44f x441x438x441x442x435x43cx430 Microsoftxae WindowsxaeProductVersion: 4.10.1998FileDescription: Windows PaintbrushOriginalFilename: PBRUSH.EXETranslation: 0x0419 0x04b0

Virus:Win95/Zofo.2784 also known as:

MicroWorld-eScan Win32.KME.Based.1.Gen
nProtect Win32.KME.Based.1.Gen
CAT-QuickHeal (Suspicious) – DNAScan
McAfee W95/KME.b
K7AntiVirus Virus
Agnitum Win95.ZMorph.2784
F-Prot W32/Wzombie.2784
Symantec W95.Zmorph.A
Norman W32/Zombie.KME.2784
TotalDefense Win95/Zombie.2784
TrendMicro-HouseCall PE_ZMORPH.2784
Avast Win32:Zombased
ClamAV W95.ZMorph.2784
Kaspersky Virus.Win9x.ZMorph.2784
BitDefender Win32.KME.Based.1.Gen
NANO-Antivirus Virus.Win32.ZMorph.bofq
ViRobot Virus.Win32.S.KME.69632
Emsisoft Virus.Win9x.ZMorph.2784.AMN (A)
Comodo Virus.Win32.KME
F-Secure Win32.KME.Based.1.Gen
DrWeb Win95.Zombie.2784
VIPRE Trojan.Win32.Generic!BT
AntiVir W32/KME.2
TrendMicro PE_ZMORPH.2784
McAfee-GW-Edition Heuristic.LooksLike.Win32.SuspiciousPE.J
Sophos W95/ZMorph-2784
Antiy-AVL Virus/Win32.Win32.gen
Kingsoft Win32.AutoInfector.a.(kcloud)
Microsoft Virus:Win95/Zofo.2784
GData Win32.KME.Based.1.Gen
Commtouch W32/Wzombie.2784
PCTools Malware.W95-Zmorph
ESET-NOD32 probably unknown TSR.WIN32
Rising Trojan.Win32.Generic.137A90B1
Ikarus Virus.Win32.Matrix
Fortinet W32/KME.C
AVG Win32/Zperm
Panda Univ.B

How to remove Virus:Win95/Zofo.2784?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Trojan.Swrort.S23689749 removal

The Trojan.Swrort.S23689749 is considered dangerous by lots of security experts. When this infection is active,…

30 mins ago

Zusy.318182 removal

The Zusy.318182 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Win32:Regrun-LY [Trj] (file analysis)

The Win32:Regrun-LY [Trj] is considered dangerous by lots of security experts. When this infection is…

2 hours ago

MSIL/Kryptik.AJRE (file analysis)

The MSIL/Kryptik.AJRE is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Trojan.Generic.35780066 removal

The Trojan.Generic.35780066 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

Win32/Agent.AFBR information

The Win32/Agent.AFBR is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago