Worm

Worm.Brontok.S73137 removal instruction

Malware Removal

The Worm.Brontok.S73137 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Brontok.S73137 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Worm.Brontok.S73137?


File Info:

name: AF1F20750388BC748AE2.mlw
path: /opt/CAPEv2/storage/binaries/448098fea2e04a65321dfbe7167f62708f7b5fbba82155911c3be8be0f108479
crc32: 0473F692
md5: af1f20750388bc748ae2da8b93ba254b
sha1: bbb6ba0a1c2284f4e57b396cb208e0d2f2b996ee
sha256: 448098fea2e04a65321dfbe7167f62708f7b5fbba82155911c3be8be0f108479
sha512: b349619afe0345f55a0c3d5e252fb70ccb0b9ef813ece8a797de5b7874632073a0ca1dc2c27758b1a21ca47a359fdd00bb9a1da50956ab54454d9060a2d819d1
ssdeep: 1536:5vDRMoORizUPliPsm/gL16ZpQGh6MgHN+PhuLGR/11Qrt3:RNxOMUMPsgQvTMY+PhGGR/11QrN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A1837D19FF82C0BCFC7109B7188976B68E23681163AD4DE317D81E645A473DBA63835B
sha3_384: 775f22402a4a97a15d17e746a57c9be899901cf26df0506a25fcf7f8c5c6f12f4196ffb1cbe8b0c266d979de4576cd97
ep_bytes: 56e8840000008bf0e849000000680c00
timestamp: 2006-03-15 22:21:26

Version Info:

0: [No Data]

Worm.Brontok.S73137 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLM.Jowo
MicroWorld-eScanWin32.Worm.Brontok.AM
FireEyeGeneric.mg.af1f20750388bc74
CAT-QuickHealWorm.Brontok.S73137
ALYacWin32.Worm.Brontok.AM
CylanceUnsafe
ZillyaWorm.Brontok.Win32.1299
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderThetaAI:Packer.8F16997B1E
CyrenW32/Backdoor.VXCQ-7763
SymantecW32.Rontokbro@mm
ESET-NOD32Win32/Pazetus.G
APEXMalicious
ClamAVWin.Worm.Brontok-9815928-0
KasperskyEmail-Worm.Win32.Brontok.o
BitDefenderWin32.Worm.Brontok.AM
NANO-AntivirusTrojan.Win32.Brontok.ldoqd
AvastWin32:Trojano-BWK [Trj]
TencentMalware.Win32.Gencirc.10ce57ec
Ad-AwareWin32.Worm.Brontok.AM
SophosML/PE-A + W32/Brontok-BB
ComodoWorm.Win32.Pazetus.s@4t3nqq
VIPRETrojan.Win32.Generic!SB.0
TrendMicroWORM_RONTKBR.GEN
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.mm
EmsisoftWin32.Worm.Brontok.AM (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Brontok.AM
JiangminWorm.Brontok.ds
AviraWORM/Brontok.N.1
Antiy-AVLTrojan/Generic.ASMalwS.E6552
ViRobotI-Worm.Win32.A.Brontok.85952
MicrosoftWorm:Win32/Brontok.BJ@mm
CynetMalicious (score: 100)
AhnLab-V3Win32/Brontok.worm.81920.E
Acronissuspicious
McAfeeW32/Rontokbro.c.gen@MM
MAXmalware (ai score=88)
VBA32Worm.Brontok
MalwarebytesWorm.Brontok
TrendMicro-HouseCallWORM_RONTKBR.GEN
RisingWorm.Brontok!1.9EB8 (CLASSIC)
YandexWorm.Brontok.Gen.1
eGambitUnsafe.AI_Score_99%
FortinetW32/Brontok.AM!worm
AVGWin32:Trojano-BWK [Trj]
Cybereasonmalicious.50388b
PandaW32/Brontok.AN.worm
MaxSecureWorm.Brontok.n

How to remove Worm.Brontok.S73137?

Worm.Brontok.S73137 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment