Worm

Worm:Win32/Ructo.F malicious file

Malware Removal

The Worm:Win32/Ructo.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Ructo.F virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify the Microsoft attachment manager possibly to bypass security checks on mail and Internet saved files
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics

How to determine Worm:Win32/Ructo.F?


File Info:

name: 76F5511062CC13F55911.mlw
path: /opt/CAPEv2/storage/binaries/69bca1bb770e6e993f18f8518cbfc11c442bbb30354248c6f92869b224102187
crc32: 1AD9C6AC
md5: 76f5511062cc13f559117679b64c68c1
sha1: 1e80a6406e1a20779e299b1b1b4a49528056e692
sha256: 69bca1bb770e6e993f18f8518cbfc11c442bbb30354248c6f92869b224102187
sha512: 9de04fb5b914665ce2f0da9075e01170ede536b45ecc61c2282cae92656dd222de2829b3d39b2274882940eec31e075f7ba27f58d624dcdd9fb94ae585e02930
ssdeep: 6144:qhjCDWSKSD/I+3yR5XS1CfdZpCTXHcwJNqV1X:qEDPQ6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15AB4A61FE5AC6211F911D4393DB59A6B5C923C3F2380A81EF6596B9539B49C3F0B022F
sha3_384: 88b6357c958e6e6b458c1e3573e9ae038ba4603e7f50db4e89c67cc187260068134d3e83f5a58aec5e9b9220ee147a26
ep_bytes: 68c0284000e8f0ffffff000000000000
timestamp: 2001-08-17 20:52:32

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Particular
ProductName: ProjectWmplayer
FileVersion: 1.00
ProductVersion: 1.00
InternalName: project1
OriginalFilename: project1.exe

Worm:Win32/Ructo.F also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vilsel.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Generic.3105
MicroWorld-eScanGen:Trojan.Heur.Fi0@sL5RyBciu
FireEyeGeneric.mg.76f5511062cc13f5
SkyhighBehavesLike.Win32.Vilsel.hz
McAfeeGeneric VB.dv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Heur.Fi0@sL5RyBciu
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 00171bc41 )
AlibabaWorm:Win32/Vilsel.a6c83927
K7GWTrojan ( 00171bc41 )
Cybereasonmalicious.062cc1
BitDefenderThetaAI:Packer.BDBCDAE81D
VirITTrojan.Win32.Generic.AANS
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/VB.NTU
APEXMalicious
ClamAVWin.Trojan.Vilsel-9762776-0
KasperskyTrojan.Win32.Vilsel.afwc
BitDefenderGen:Trojan.Heur.Fi0@sL5RyBciu
NANO-AntivirusTrojan.Win32.Vilsel.edsdxj
AvastWin32:Bancos-BUS [Trj]
RisingTrojan.Win32.VBCode.fir (CLASSIC)
EmsisoftGen:Trojan.Heur.Fi0@sL5RyBciu (B)
F-SecureTrojan.TR/VB.Downloader.Gen
BaiduWin32.Worm.VB.sn
ZillyaTrojan.Vilsel.Win32.16999
TrendMicroWORM_RUCTO.SMI
SophosMal/VB-S
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=100)
GDataGen:Trojan.Heur.Fi0@sL5RyBciu
JiangminTrojan/Vilsel.adnb
GoogleDetected
AviraTR/VB.Downloader.Gen
VaristW32/Ructo.A.gen!Eldorado
Antiy-AVLTrojan/Win32.Vilsel
KingsoftWin32.HeurC.KVM006.a
XcitiumTrojWare.Win32.Downloader.VB.RAB@20g50d
ArcabitTrojan.Heur.E829DA
ZoneAlarmTrojan.Win32.Vilsel.afwc
MicrosoftWorm:Win32/Ructo.F
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MSNPass.R1900
VBA32Trojan.VBRA.05453
ALYacGen:Trojan.Heur.Fi0@sL5RyBciu
TACHYONTrojan/W32.VB-Vilsel.520192.C
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_RUCTO.SMI
TencentMalware.Win32.Gencirc.10b7207e
YandexTrojan.GenAsa!tVrd91tF/G8
IkarusTrojan.Win32.Antavmu
MaxSecureTrojan.Vilsel.agwm
FortinetW32/VB.OBS!tr
AVGWin32:Bancos-BUS [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[downloader]:Win/Vilsel.afwc

How to remove Worm:Win32/Ructo.F?

Worm:Win32/Ructo.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment