Worm

Worm:Win32/Rombrast removal

Malware Removal

The Worm:Win32/Rombrast is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Rombrast virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Rombrast?


File Info:

name: C615FD95A34A3B2BDAC4.mlw
path: /opt/CAPEv2/storage/binaries/8b3dd681ce37a372784985ca7268fa2c7ec932d131d94bcdbd29d51375b97d8b
crc32: 0A2B8308
md5: c615fd95a34a3b2bdac4fb9938d1f3fc
sha1: 165b51931b2273cad09851ea0f41c9eae69bc7b6
sha256: 8b3dd681ce37a372784985ca7268fa2c7ec932d131d94bcdbd29d51375b97d8b
sha512: 1c756229dcba0fade618bbc92a69b59e303a9e6760aa527aabf77e4bc44e9f133f87154836666f6bbf3725a2a92406a0786819cf85b929358a01165dfe71a322
ssdeep: 1536:7Qcw0gn7XNe/z5i2SNnx9heoaWFP2WIL5/CuU5Jr5ug5i5J5i5Vji8O+w+HW7PM7:UHXNQSeoHn/zOjVypqW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14404C42E24BCACA3FB5D42BF4AD1C0FB0383B91D2B528933194A970E5E7B591771161B
sha3_384: 9f640e46b89879bcc07aad44263d5c2259bc235685fd1f449406afdfa77224a65da65e1b9f99571cc169d4d2f4fd9863
ep_bytes: 684c4d4000e8eeffffff000000000000
timestamp: 2012-10-07 00:28:56

Version Info:

Translation: 0x0409 0x04b0
CompanyName: ProviamoUno
LegalCopyright: Ammazza che beddo
ProductName: caruso minnooka
FileVersion: 1.02.0001
ProductVersion: 1.02.0001
InternalName: a
OriginalFilename: a.exe

Worm:Win32/Rombrast also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Brresmon.Gen.1
FireEyeGeneric.mg.c615fd95a34a3b2b
CylanceUnsafe
SangforVISUAL BASIC4
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.Generic.CEYN
ESET-NOD32Win32/AutoRun.Agent.AGC
APEXMalicious
ClamAVWin.Trojan.Repyh-6853499-0
KasperskyTrojan-Dropper.Win32.Injector.fwsh
BitDefenderGen:Trojan.Brresmon.Gen.1
NANO-AntivirusTrojan.Win32.Inject.djxafy
AvastWin32:Carberp-AOV [Trj]
Ad-AwareGen:Trojan.Brresmon.Gen.1
SophosML/PE-A + Mal/VBLoad-A
DrWebTrojan.DownLoader7.2463
ZillyaDropper.Injector.Win32.39907
TrendMicroTROJ_JORIK.SM4
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Brresmon.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Brresmon.Gen.1
JiangminTrojanDropper.Injector.aoav
AviraTR/Crypt.XPACK.Gen
ZoneAlarmTrojan-Dropper.Win32.Injector.fwsh
MicrosoftWorm:Win32/Rombrast
CynetMalicious (score: 100)
AhnLab-V3Win32/Rombrast.worm.102400
BitDefenderThetaGen:NN.ZevbaF.34742.k80@a8!MvTv
MAXmalware (ai score=80)
VBA32TrojanDropper.Injector
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallTROJ_JORIK.SM4
RisingTrojan.VBInject!1.9E7B (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Zbot.IFV!tr
AVGWin32:Carberp-AOV [Trj]
Cybereasonmalicious.5a34a3
PandaGeneric Suspicious

How to remove Worm:Win32/Rombrast?

Worm:Win32/Rombrast removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment