Worm

Worm:Win32/Brontok!pz removal

Malware Removal

The Worm:Win32/Brontok!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Brontok!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Brontok!pz?


File Info:

name: EF61036025741259C99F.mlw
path: /opt/CAPEv2/storage/binaries/24c833b28ee1058f37035c9d8c144c246e5241a1bac2c9d106f9f45d480ce51f
crc32: 903921D2
md5: ef61036025741259c99f1c711fc01068
sha1: 9c0eea38b12c87b87478a8c739b70029760c320f
sha256: 24c833b28ee1058f37035c9d8c144c246e5241a1bac2c9d106f9f45d480ce51f
sha512: 0a939f063f6ed0dff51fd9e764ce30253f44a52b57e5ab06a08ae70d2c23a62318c695e299520678ad5becdf4dc063d36587278b577be00274619d81f6edef05
ssdeep: 768:5igkgs9PuO7wd/xAfCK3j/7ZEEALZGXwnvN5BMC:5Hs9uOEdcCK3z7ZEE6GXwl5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E139E13631CCACEC57526759D3C15AA7FE93C268436E2AA9C86BE077CF1C636CC1582
sha3_384: 9578b6d8c8d791a0bf5d62c2029e8056a02e86e970a8b58c5ea6d57abae631d20cd693cc907a3e6710af8e26b783243a
ep_bytes: 40929092924a92baf0604100ffd2b8f0
timestamp: 2006-03-15 21:45:53

Version Info:

0: [No Data]

Worm:Win32/Brontok!pz also known as:

BkavW32.RontokbroER.Worm
LionicWorm.Win32.Brontok.la0V
Elasticmalicious (high confidence)
DrWebWin32.HLLM.Brontok
MicroWorld-eScanWin32.Worm.Brontok.CC
ClamAVWin.Worm.Brontok-10
FireEyeWin32.Worm.Brontok.CC
CAT-QuickHealW32.Brontok.N
SkyhighBehavesLike.Win32.Generic.pc
McAfeeW32/Rontokbro.d.gen@MM
ZillyaWorm.Brontok.Win32.7
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Brontok.c3e0aaba
K7GWEmailWorm ( 0053178c1 )
K7AntiVirusEmailWorm ( 0053178c1 )
VirITI-WORM.Brontok.E
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
KasperskyEmail-Worm.Win32.Brontok.n
BitDefenderWin32.Worm.Brontok.CC
SUPERAntiSpywareTrojan.Agent/Gen-Krotche
AvastWin32:Brontok-U [Wrm]
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
TACHYONWorm/W32.Brontok.43520
EmsisoftWin32.Worm.Brontok.CC (B)
F-SecureWorm.WORM/Brontok.I
BaiduWin32.Worm.Pazetus.a
VIPREWin32.Worm.Brontok.CC
SophosW32/Rontokbr-A
IkarusVirus.Alman
GDataWin32.Trojan.PSE1.THRS28
JiangminBackdoor/SdBot.daj
GoogleDetected
AviraWORM/Brontok.I
Antiy-AVLWorm[Email]/Win32.Brontok.n
XcitiumWorm.Win32.Pazetus.J@4hp2
ArcabitWin32.Worm.Brontok.CC
ViRobotI-Worm.Win32.Brontok.43072.J
ZoneAlarmEmail-Worm.Win32.Brontok.n
MicrosoftWorm:Win32/Brontok!pz
VaristW32/Brontok.VEUU-7803
AhnLab-V3Worm/Win32.Brontok.R1815
ALYacWin32.Worm.Brontok.CC
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Brontok.AQ.worm
TencentEmail-Worm.Win32.Brontok.wa
YandexWorm.Brontok.BA
SentinelOneStatic AI – Malicious PE
MaxSecureEmail-Worm.Brontok.Gen
FortinetW32/Generic.AC.1393!tr
AVGWin32:Brontok-U [Wrm]
Cybereasonmalicious.8b12c8
DeepInstinctMALICIOUS

How to remove Worm:Win32/Brontok!pz?

Worm:Win32/Brontok!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment