Malware

Dropped:Win32.Virlock.Gen.4 information

Malware Removal

The Dropped:Win32.Virlock.Gen.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Win32.Virlock.Gen.4 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Dropped:Win32.Virlock.Gen.4?


File Info:

name: DF3B27432F87CBFEB0A8.mlw
path: /opt/CAPEv2/storage/binaries/15fa20e389c6bc1c2a4f65eba9f80907110b2926e8b1fa1e74707b9a93ce3665
crc32: 1FCD4A71
md5: df3b27432f87cbfeb0a85416f470e557
sha1: b941be9f32c431f89fb773c582286f25ca2a805a
sha256: 15fa20e389c6bc1c2a4f65eba9f80907110b2926e8b1fa1e74707b9a93ce3665
sha512: d2e6842bb0f981773aa1ba259590fb27f163c3cdc067cf9a33b846b6ecb3c3e568d82e42fea025dd43c6a1bc45c3f7e1c199c436190933f477fd3e1aab1c3440
ssdeep: 3072:mzMi6T1oY517JQY5AJy5FoZhwHPk6TLu/8uzecdV/Klrv:JiUoq7FJPAUuvjIj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12DD3CEB6AA459772F53B4B352FD7A226AA257D2F3370A52C84460E0F741A0F6D8D703C
sha3_384: e908235eed1265769b04f0d5e575d487bee3993c7bf0405603503183cdf41b2b1182fdc26029e3c97acd5efe8c50a96a
ep_bytes: bae0a90800b8a055070081ea068e0400
timestamp: 1970-01-01 00:02:03

Version Info:

0: [No Data]

Dropped:Win32.Virlock.Gen.4 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Virlock.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Win32.Virlock.Gen.4
FireEyeGeneric.mg.df3b27432f87cbfe
SkyhighBehavesLike.Win32.VirRansom.cc
McAfeeW32/VirRansom
MalwarebytesGeneric.Malware.AI.DDS
VIPREDropped:Win32.Virlock.Gen.4
SangforRansom.Win32.Save.a
K7AntiVirusVirus ( 0040f99f1 )
AlibabaRansom:Win32/Polyransom.A
K7GWVirus ( 0040f99f1 )
Cybereasonmalicious.f32c43
ArcabitWin32.Virlock.Gen.4
BaiduWin32.Virus.Virlock.a
VirITWin32.CryptorGen.B
SymantecW32.Virlock!inf
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Virlock.D
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.PolyRansom.a
BitDefenderDropped:Win32.Virlock.Gen.4
NANO-AntivirusTrojan.Win32.Kryptik.dmrlkh
AvastWin32:VirLock [Inf]
TencentVirus.Win32.VirLocker.b
TACHYONVirus/W32.VirRansom.C
SophosW32/VirRnsm-A
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebWin32.VirLock.2
ZillyaVirus.PolyRansom.Win32.1
TrendMicroPE_VIRLOCK.C
EmsisoftDropped:Win32.Virlock.Gen.4 (B)
IkarusVirus-Ransom.FileLocker
JiangminWin32/Polyransom.a
VaristW32/S-27bc0672!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLVirus/Win32.PolyRansom.a
GridinsoftVirus.Win32.Wlock.sa
XcitiumPacked.Win32.Graybird.B@5hgpd5
MicrosoftVirus:Win32/Nabucur.A
ZoneAlarmVirus.Win32.PolyRansom.a
GDataDropped:Win32.Virlock.Gen.4
GoogleDetected
Acronissuspicious
BitDefenderThetaAI:Packer.410AD9CA1F
ALYacDropped:Win32.Virlock.Gen.4
MAXmalware (ai score=87)
VBA32Virus.VirLock
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPE_VIRLOCK.C
RisingTrojan.Vindor!8.10CC (TFE:2:RUUyfJLMoeL)
YandexVirus.Virlock.Gen.AAJ
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.PolyRansom.a
FortinetW32/Virlock.K
AVGWin32:VirLock [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Dropped:Win32.Virlock.Gen.4?

Dropped:Win32.Virlock.Gen.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment