Malware

Should I remove “Malware.Heuristic.2051”?

Malware Removal

The Malware.Heuristic.2051 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.Heuristic.2051 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.Heuristic.2051?


File Info:

name: 8C920C186ABB2966B188.mlw
path: /opt/CAPEv2/storage/binaries/524a3bc4f9634b72de2f754f5d64bd19b6bf38446a6479f73b730bd05d695a8a
crc32: DCCFD55B
md5: 8c920c186abb2966b1883f90e108c7bf
sha1: 403b254312acebd14957db22dc3de665373e22ff
sha256: 524a3bc4f9634b72de2f754f5d64bd19b6bf38446a6479f73b730bd05d695a8a
sha512: 2c1532f1745f5eceb0fa482fb6950208dbf8176f4b09f0964ea760eb68b83903a9299e50392410f914a633ee552eb0ac5b297e70ff76521ae97a57d0727edd71
ssdeep: 6144:A5b9ig3Xo09BxubiP6yp5fCmqnRS7nA36uhftA7iyxT/3QGvt:A5bckOyORG9+fai4/3b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13724CFF60747E02ED16942B68A872E8D7E6C4CEC4E65DBB233481BDB0A91D4C1FCB591
sha3_384: 2d2fbe83f353fe1604f5aa4bdc92a9a2846070d95e81701f4fa3e69f06f193f600bc04c5501089c32816e18c83034cae
ep_bytes: be41110c00bb1892010081c6128e0000
timestamp: 1970-01-01 00:02:03

Version Info:

0: [No Data]

Malware.Heuristic.2051 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Virlock.n!c
tehtrisGeneric.Malware
DrWebWin32.VirLock.2
MicroWorld-eScanWin32.Virlock.Gen.4
FireEyeGeneric.mg.8c920c186abb2966
SkyhighBehavesLike.Win32.VirRansom.dc
McAfeeW32/VirRansom
Cylanceunsafe
ZillyaVirus.PolyRansom.Win32.1
SangforRansom.Win32.Save.a
K7AntiVirusVirus ( 0040f99f1 )
K7GWVirus ( 0040f99f1 )
Cybereasonmalicious.86abb2
BitDefenderThetaAI:FileInfector.30FD658313
VirITWin32.CryptorGen.B
SymantecW32.Virlock!inf
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Virlock.D
APEXMalicious
TrendMicro-HouseCallPE_VIRLOCK.J
KasperskyVirus.Win32.PolyRansom.a
BitDefenderWin32.Virlock.Gen.4
NANO-AntivirusTrojan.Win32.Kryptik.dmrlkh
AvastWin32:VirLock [Inf]
RisingTrojan.Upatre!8.648F (TFE:2:LLwKZf45iNI)
TACHYONVirus/W32.VirRansom.C
EmsisoftWin32.Virlock.Gen.4 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
BaiduWin32.Virus.Virlock.a
VIPREWin32.Virlock.Gen.4
TrendMicroPE_VIRLOCK.J
Trapminemalicious.high.ml.score
SophosW32/VirRnsm-A
IkarusVirus-Ransom.FileLocker
JiangminWin32/Polyransom.a
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/S-4ab5d27b!Eldorado
Antiy-AVLVirus/Win32.PolyRansom.a
MicrosoftVirus:Win32/Nabucur.A
XcitiumPacked.Win32.Graybird.B@5hgpd5
ArcabitWin32.Virlock.Gen.4
ZoneAlarmVirus.Win32.PolyRansom.a
GDataWin32.Virlock.Gen.4
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C638970
Acronissuspicious
ALYacWin32.Virlock.Gen.4
MAXmalware (ai score=89)
MalwarebytesMalware.Heuristic.2051
PandaGeneric Suspicious
TencentVirus.Win32.VirLocker.b
YandexVirus.Virlock.Gen.AAJ
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.PolyRansom.a
FortinetW32/Virlock.K
AVGWin32:VirLock [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirus:Win/Virlock.e(dyn)

How to remove Malware.Heuristic.2051?

Malware.Heuristic.2051 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment