Malware

Dropped:Win32.Virlock.Gen.4 malicious file

Malware Removal

The Dropped:Win32.Virlock.Gen.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Win32.Virlock.Gen.4 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Dropped:Win32.Virlock.Gen.4?


File Info:

name: 729B056F59EB6DEAFE3E.mlw
path: /opt/CAPEv2/storage/binaries/1535be272cce5258939cd8289ebdb736a0555a611a30e9e0676302b2610c52c9
crc32: DB8F064C
md5: 729b056f59eb6deafe3e59666907b556
sha1: 26408ff7856dc3ca35e9dc5cf6425555e0922a38
sha256: 1535be272cce5258939cd8289ebdb736a0555a611a30e9e0676302b2610c52c9
sha512: ead30827cf3c07fe12969cb0f2961a8adfc7989ff185128f14124718f2c6441878780cd28cdf57a92b66c5e32a4e755abe2a51b9959669aed8462948dd9ee23f
ssdeep: 12288:SHrubl2JhnsWtNwNLHFjFxUWdJBNCwzvc2w/tX:SLubgbnUJddC4vE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164C4AF339AC0FC04851D4E7ECDEA2879424FC787596B19B820B9F193A7261523FD866F
sha3_384: ca7a78d2717710c3436d4c89a8adcd0f3e2590a41f5a865eaa71a1687c4526e42c08b51edfe217effed55f9389f04e65
ep_bytes: ba1f9a0600bbf6cf030081eac3120c00
timestamp: 1970-01-01 00:02:03

Version Info:

0: [No Data]

Dropped:Win32.Virlock.Gen.4 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.VirLock.2
MicroWorld-eScanDropped:Win32.Virlock.Gen.4
CAT-QuickHealRansom.PolyRansom.B2
SkyhighBehavesLike.Win32.VirRansom.hc
McAfeeW32/VirRansom
MalwarebytesGeneric.Malware.AI.DDS
VIPREDropped:Win32.Virlock.Gen.4
SangforRansom.Win32.Save.a
K7AntiVirusVirus ( 0040f99f1 )
K7GWVirus ( 0040f99f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.FC7261841D
VirITWin32.CryptorGen.B
SymantecW32.Virlock!inf
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Virlock.D
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.PolyRansom.a
BitDefenderDropped:Win32.Virlock.Gen.4
NANO-AntivirusTrojan.Win32.Kryptik.dmrlkh
AvastWin32:VirLock [Inf]
TencentVirus.Win32.VirLocker.b
EmsisoftDropped:Win32.Virlock.Gen.4 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
BaiduWin32.Virus.Virlock.a
ZillyaVirus.PolyRansom.Win32.1
TrendMicroPE_VIRLOCK.C
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.729b056f59eb6dea
SophosW32/VirRnsm-A
SentinelOneStatic AI – Malicious PE
GDataDropped:Win32.Virlock.Gen.4
JiangminWin32/Polyransom.a
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=80)
Antiy-AVLVirus/Win32.PolyRansom.a
XcitiumPacked.Win32.Graybird.B@5hgpd5
ArcabitWin32.Virlock.Gen.4
ZoneAlarmVirus.Win32.PolyRansom.a
MicrosoftVirus:Win32/Nabucur.A
VaristW32/S-27bc0672!Eldorado
Acronissuspicious
VBA32Virus.VirLock
ALYacDropped:Win32.Virlock.Gen.4
TACHYONVirus/W32.VirRansom.C
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPE_VIRLOCK.C
RisingTrojan.Vindor!8.10CC (TFE:2:Mo3MqKZRl5F)
YandexVirus.Virlock.Gen.AAJ
IkarusVirus-Ransom.FileLocker
MaxSecureVirus.PolyRansom.a
FortinetW32/Virlock.K
AVGWin32:VirLock [Inf]
Cybereasonmalicious.7856dc
DeepInstinctMALICIOUS

How to remove Dropped:Win32.Virlock.Gen.4?

Dropped:Win32.Virlock.Gen.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment