Worm

Worm:Win32/Bruhorn!pz (file analysis)

Malware Removal

The Worm:Win32/Bruhorn!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Bruhorn!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to disable or modify Explorer Folder Options
  • Attempts to disable System Restore
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Bruhorn!pz?


File Info:

name: 2377C42D671514E77F64.mlw
path: /opt/CAPEv2/storage/binaries/0523e86d192616c9f72733aa9786c1b9cf12708235d17276815c1db6e481ad6d
crc32: 6B67E0F5
md5: 2377c42d671514e77f64ee2dbe98f2da
sha1: d85b524526e5372372a398a2a413d78ab7e7531b
sha256: 0523e86d192616c9f72733aa9786c1b9cf12708235d17276815c1db6e481ad6d
sha512: 8478eb960e3d86a535dc1c2d749aa4a4c1af686d486f1dfab4ec19a7a20233bef180533951deb2573d4064faa7f84a398c3a7680f7e3030aefe7415100bc5130
ssdeep: 3072:J/5F/E7tEf0h+s+tYlpJH7iXQNgggHlxDZiYLK5WplwS45r4wS4q:JhF4cE+vWJH7igNgjdFKs65r4qq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E82429693390E339E21685F83A219268549EFC3005EA9C1FDBC36B167AB5DD3E630753
sha3_384: 92d366f5ee25e29162d032e48a8e139b0407a59564d5675de486ea7f740882dd8dd52fabcafc2a7d720ae157ce894ea8
ep_bytes: 68a8444000e8eeffffff000000000000
timestamp: 2006-11-27 09:24:01

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Oncom
ProductName: xk
FileVersion: 0.00.0020
ProductVersion: 0.00.0020
InternalName: DATA
OriginalFilename: DATA.exe

Worm:Win32/Bruhorn!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWorm.Ludbaruma.B
SkyhighBehavesLike.Win32.Vilsel.dm
McAfeeW32/Rontokbro.gen@MM
MalwarebytesGeneric.Malware.AI.DDS
VIPREWorm.Ludbaruma.B
SangforRansom.Win32.Foreign_11.se
K7AntiVirusTrojan ( 0040f6141 )
K7GWP2PWorm ( 0050fa4b1 )
BaiduWin32.Worm.VB.k
SymantecBloodhound.W32.VBWORM
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.ORD
APEXMalicious
TrendMicro-HouseCallRansom_Blocker.R03BC0CDO24
ClamAVWin.Worm.Ludbaruma-10013350-0
KasperskyTrojan-Ransom.Win32.Blocker.kpuo
BitDefenderWorm.Ludbaruma.B
NANO-AntivirusTrojan.Win32.Regrun.dxtouo
SUPERAntiSpywareWorm.Ludbaruma/Variant
AvastWin32:Malware-gen
TencentTrojan.Win32.Blocker.wd
EmsisoftWorm.Ludbaruma.B (B)
F-SecureTrojan.TR/Agent.gdnw
DrWebTrojan.DownLoader7.3730
ZillyaTrojan.RegrunGen.Win32.1
TrendMicroRansom_Blocker.R03BC0CDO24
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.2377c42d671514e7
SophosW32/Mato-N
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
JiangminTrojan.Blocker.tav
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Agent.gdnw
VaristW32/VB-Backdoor-HRS-based!Maxim
Antiy-AVLGrayWare/Win32.Agent.ojw
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Bruhorn!pz
XcitiumTrojWare.Win32.Injector.FZZA@57zyc0
ArcabitWorm.Ludbaruma.B
ZoneAlarmTrojan-Ransom.Win32.Blocker.kpuo
GDataWin32.Worm.Ludbaruma.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Blocker.R570283
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacWorm.Ludbaruma.B
TACHYONTrojan/W32.VB-Ludbaruma.Zen.C
Cylanceunsafe
PandaTrj/CI.A
ZonerTrojan.Win32.70598
RisingWorm.Ludbaruma!1.BDC8 (CLASSIC)
YandexTrojan.GenAsa!3Dzo+yWZn14
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Regrun.PKE!tr
BitDefenderThetaAI:Packer.72BF9EE11D
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Ludbaruma

How to remove Worm:Win32/Bruhorn!pz?

Worm:Win32/Bruhorn!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment