Ransom

Ransom.VirLock.42 (file analysis)

Malware Removal

The Ransom.VirLock.42 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.VirLock.42 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.VirLock.42?


File Info:

name: D652D477910EA5F0F69A.mlw
path: /opt/CAPEv2/storage/binaries/c84c409bde6769a9b68a953ef2ac20d3426ed1c73b9c3c0472767fb28cf3fee4
crc32: EF74CD94
md5: d652d477910ea5f0f69ab50086d0d806
sha1: d1b087bd05fa40ada598b03a19aac428c5b889ea
sha256: c84c409bde6769a9b68a953ef2ac20d3426ed1c73b9c3c0472767fb28cf3fee4
sha512: b7e387168cdce00385eb47f4f82d7af6e3e544672e6ce66da490d5d9d7005be306ede6548428d2eae4a8c3b3c52b34049729712eb0bd96328ad0c1b76f392022
ssdeep: 24576:nTlP7gSzpAVWVtI3K344pXkeD/k34bQ7b2ROIVVXezqElDz:5P7gSzpAEVtI6xVkw834bQneO8Ozqs/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121759DB08516C061DA9B2BFD9447478D01EC8E1063EE18F29576BDC09FB2E3ED14B99E
sha3_384: db7c6d9d8a8425ed3c8217caa66bbc390b3d2e334951b0d187fed3f898561484d49f8a7bd7a11d084d519f950dd6a682
ep_bytes: 0bce23df0bf90bd9e86613180087d903
timestamp: 2015-01-06 00:36:08

Version Info:

0: [No Data]

Ransom.VirLock.42 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.PolyRansom.mfPW
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ransom.VirLock.42
FireEyeGeneric.mg.d652d477910ea5f0
SkyhighBehavesLike.Win32.VirRansom.th
McAfeeGeneric Obfuscated.g
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ransom.VirLock.42
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 00573f0e1 )
BitDefenderGen:Variant.Ransom.VirLock.42
K7GWTrojan ( 00573f0e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.6AAF637A1F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Virlock.AJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Virus.Virlock-6332874-0
KasperskyVirus.Win32.PolyRansom.b
AlibabaRansom:Win32/PolyRansom.bfc39080
NANO-AntivirusTrojan.Win32.Gena.doticp
AvastWin32:SwPatch [Wrm]
RisingVirus.VirLock!1.A08A (CLASSIC)
TACHYONVirus/W32.VirRansom
EmsisoftGen:Variant.Ransom.VirLock.42 (B)
BaiduWin32.Virus.Virlock.a
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Packed
Trapminemalicious.moderate.ml.score
SophosMal/EncPk-NS
IkarusVirus.Win32.Virlock
VaristW32/Virlock.N.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLGrayWare/Win32.VirLock.a
Kingsoftmalware.kb.a.998
MicrosoftVirus:Win32/Nabucur.A
XcitiumTrojWare.Win32.Virlock.XU@5xaovq
ArcabitTrojan.Ransom.VirLock.42
ZoneAlarmVirus.Win32.PolyRansom.b
GDataGen:Variant.Ransom.VirLock.42
GoogleDetected
AhnLab-V3Trojan/Win32.Virlock.R355222
Acronissuspicious
VBA32Virus.VirLock
ALYacGen:Variant.Ransom.VirLock.42
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
TencentWin32.Virus.Polyransom.Czlw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Virlock.B
AVGWin32:SwPatch [Wrm]
DeepInstinctMALICIOUS

How to remove Ransom.VirLock.42?

Ransom.VirLock.42 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment