Malware

Dropped:Win32.Virlock.Gen.4 removal guide

Malware Removal

The Dropped:Win32.Virlock.Gen.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Win32.Virlock.Gen.4 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Dropped:Win32.Virlock.Gen.4?


File Info:

name: FD1D34D5E2F3B9C851A0.mlw
path: /opt/CAPEv2/storage/binaries/dbc26323e4775e3399e079407e110930df3a8d432c9c7d87115d3ed73c548f06
crc32: BE36101C
md5: fd1d34d5e2f3b9c851a0ac08243ca1ab
sha1: 68868cea20547062e731b3269a860ffdedf38950
sha256: dbc26323e4775e3399e079407e110930df3a8d432c9c7d87115d3ed73c548f06
sha512: d57a0aedaba1c127d39053f5489b6eed3a4bdc3a2592331840d0733c0f0e5b1a99f829f8eede75feb8124dfa1ba7f979ac8b93b61c893deb5e562727ff989d15
ssdeep: 6144:6jh1gnURg9Acrk8RQtl9tzgID+1hBm5dFMSIO07:6duSgR9RQtl93QB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C44E356285B1CD392E3E1201CF4F533C1AE2E2AD6B66F950A2E5FBC5D388FA35441E1
sha3_384: ffc0c50d79fa0b6841b1f9d2fa64a63d661b4ddc5bd971b34d21c0cbba3c613dde7e12eb92f24fe99426f2f016a01ab6
ep_bytes: bef7890e00b992bf020081eec73a0500
timestamp: 1970-01-01 00:02:03

Version Info:

0: [No Data]

Dropped:Win32.Virlock.Gen.4 also known as:

BkavW32.AIDetectMalware
AVGWin32:VirLock [Inf]
Elasticmalicious (high confidence)
DrWebWin32.VirLock.2
MicroWorld-eScanDropped:Win32.Virlock.Gen.4
FireEyeGeneric.mg.fd1d34d5e2f3b9c8
SkyhighBehavesLike.Win32.VirRansom.dc
McAfeeW32/VirRansom
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.PolyRansom.Win32.1
SangforRansom.Win32.Save.a
K7AntiVirusVirus ( 0040f99f1 )
K7GWVirus ( 0040f99f1 )
Cybereasonmalicious.5e2f3b
BitDefenderThetaGen:NN.ZexaF.36802.piW@aeaF5Rfi
VirITWin32.CryptorGen.B
SymantecW32.Virlock!inf
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Virlock.D
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:VirLock [Inf]
KasperskyVirus.Win32.PolyRansom.a
BitDefenderDropped:Win32.Virlock.Gen.4
NANO-AntivirusTrojan.Win32.Kryptik.dmrlkh
TencentVirus.Win32.VirLocker.b
EmsisoftDropped:Win32.Virlock.Gen.4 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Virus.Virlock.a
VIPREDropped:Win32.Virlock.Gen.4
TrendMicroPE_VIRLOCK.C
Trapminemalicious.moderate.ml.score
SophosW32/VirRnsm-A
IkarusVirus-Ransom.FileLocker
JiangminWin32/Polyransom.a
VaristW32/S-27bc0672!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLVirus/Win32.PolyRansom.a
MicrosoftVirus:Win32/Nabucur.A
XcitiumPacked.Win32.Graybird.B@5hgpd5
ArcabitWin32.Virlock.Gen.4
ZoneAlarmVirus.Win32.PolyRansom.a
GDataDropped:Win32.Virlock.Gen.4
GoogleDetected
Acronissuspicious
VBA32Virus.VirLock
ALYacDropped:Win32.Virlock.Gen.4
TACHYONVirus/W32.VirRansom.C
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPE_VIRLOCK.C
RisingTrojan.Vindor!8.10CC (TFE:2:3gM6Nu7ce8T)
YandexVirus.Virlock.Gen.AAJ
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.PolyRansom.a
FortinetW32/Virlock.K
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudVirus:Win/Virlock.e(dyn)

How to remove Dropped:Win32.Virlock.Gen.4?

Dropped:Win32.Virlock.Gen.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment