Worm

Worm:Win32/Brontok.FFV (file analysis)

Malware Removal

The Worm:Win32/Brontok.FFV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Brontok.FFV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Brontok.FFV?


File Info:

name: 64A34F86F5D754D3DB63.mlw
path: /opt/CAPEv2/storage/binaries/24abaf05a4977f9e4c62974cc4d24de80502c5d60f990acfd38d9dbe8496b661
crc32: 11F82066
md5: 64a34f86f5d754d3db63a5d4421dea0c
sha1: 20fa282b0e540a27c426d85a6116e4d4bde3e201
sha256: 24abaf05a4977f9e4c62974cc4d24de80502c5d60f990acfd38d9dbe8496b661
sha512: 4495d367a34c993808477a8e73292c79675d8d267f494cbeccf4116733af90380457ad7bc475115cfe5aa2840c90af1539e32249df752875ba1e1f436bcc8a9c
ssdeep: 1536:srZtaewPBaF79KuUbYLKRT5YhtGzq8FtNM06lc5:sDahPBarKpbqKknGzRSq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17953E181B6035918C549983E8631C709F4B26FA04D575B6BA3C63DCABEB91D43C5B363
sha3_384: 7733c2e09482347cdc7520db2cb8042948075539fcc3007fac99d15fc66fd9ebb65ee89beb593cfa508830979dd01cdd
ep_bytes: 0c00eb066810170000c39c60e8020000
timestamp: 2002-06-25 10:10:49

Version Info:

0: [No Data]

Worm:Win32/Brontok.FFV also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.FakeFolder.A
CAT-QuickHealWorm.Brontok.FF9
SkyhighBehavesLike.Win32.Generic.kc
McAfeeW32/Rontokbro.worm.e
Cylanceunsafe
ZillyaTrojan.Pakes.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 00356cd11 )
AlibabaWorm:Win32/Brontok.d9b70bb8
K7GWEmailWorm ( 00356cd11 )
Cybereasonmalicious.b0e540
BaiduWin32.Worm.VB.oe
VirITWorm.Win32.Brontok.AC
SymantecW32.SillyFDC
ESET-NOD32Win32/VB.NJG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Fakefolder-4
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGenPack:Trojan.FakeFolder.A
NANO-AntivirusTrojan.Win32.Blank.emmbzl
AvastWin32:Pakes-BGU [Trj]
TencentMalware.Win32.Gencirc.13b571d7
EmsisoftGenPack:Trojan.FakeFolder.A (B)
F-SecureTrojan.TR/VB.anl
DrWebWin32.HLLW.Blank
VIPREGenPack:Trojan.FakeFolder.A
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGenPack:Trojan.FakeFolder.A
JiangminBackdoor/IRCBot.mef
WebrootW32.Worm.Lj
VaristW32/Backdoor.YPBO-6000
AviraTR/VB.anl
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Trojan.Pakes.cob0@1cd48i
ArcabitGenPack:Trojan.FakeFolder.A
ViRobotTrojan.Win32.Blank.34304
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Brontok.FFV
GoogleDetected
AhnLab-V3Backdoor/Win32.IRCBot.R1456
VBA32Trojan.VBRA.02297
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderP
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
YandexWorm.VB.FMU
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/IRCBot.PBR!tr
BitDefenderThetaAI:Packer.E57AB8E41D
AVGWin32:Pakes-BGU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Brontok.FFV?

Worm:Win32/Brontok.FFV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment