Ransom

Should I remove “Ransom.VirLock.66”?

Malware Removal

The Ransom.VirLock.66 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.VirLock.66 virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ransom.VirLock.66?


File Info:

name: 6A33AEF72C143E48B1CE.mlw
path: /opt/CAPEv2/storage/binaries/3f29aff79316c91e8c69b9950056726fc18fe9b9f8ff4df45436b2be30f10421
crc32: 2F786A34
md5: 6a33aef72c143e48b1cee0fe9b4b64c4
sha1: 1f6367129ddd1da97d36586420deadb74ccdebe9
sha256: 3f29aff79316c91e8c69b9950056726fc18fe9b9f8ff4df45436b2be30f10421
sha512: 798e614b30098243b06ae8362b0c25528d6a1059999e1ccc021381ffb666296af2b1dcaef2803c232f296d0337d3224c02a991a9ec6e292c98643fe1bc290097
ssdeep: 12288:jUffQoBsbB9+BDgZnFin4FcWHS5jBkBi3pHE6sOAU/3NoTnjdeWQGRMG:jS3sbBqJn4F3zi3pHE6CU/3kexGRMG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197F401D438563B53CA81FFBD47D2A72462C881989B5836E7FD52EDD8212A3E264FC10D
sha3_384: 4adb1f9e342a4d86b17123785958cb1dbcacb81fb2d3c08638b6f89794bf0e43205abfe8f73f38e951ef961eae45c42f
ep_bytes: e8047f11003d03ffffff0f8506000000
timestamp: 2015-02-07 09:53:36

Version Info:

0: [No Data]

Ransom.VirLock.66 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mikey.4!c
MicroWorld-eScanGen:Variant.Ransom.VirLock.66
ClamAVWin.Virus.Virlock-6804475-0
FireEyeGeneric.mg.6a33aef72c143e48
SkyhighBehavesLike.Win32.VirRansom.bc
ALYacGen:Variant.Ransom.VirLock.66
ZillyaVirus.Virlock.Win32.1
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 004df38e1 )
K7GWTrojan ( 004df38e1 )
Cybereasonmalicious.29ddd1
BaiduWin32.Virus.Virlock.e
SymantecW32.Virlock!inf6
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Virlock.AN
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Ransom.VirLock.66
TencentWin32.Virus.Virlock.Sgil
EmsisoftGen:Variant.Ransom.VirLock.66 (B)
VIPREGen:Variant.Ransom.VirLock.66
TrendMicroPE_VIRLOCK.I
SophosW32/VirRnsm-C
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ransom.VirLock.66
JiangminWin32/Polyransom.f
GoogleDetected
Antiy-AVLGrayWare/Win32.VirLock.a
XcitiumVirus.Win32.Virlock.jet@5jiemd
ArcabitTrojan.Ransom.VirLock.66
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/S-5bc70eb6!Eldorado
AhnLab-V3Win32/Nabucur.D.X1505
Acronissuspicious
McAfeeW32/VirRansom.b
MAXmalware (ai score=87)
MalwarebytesVirlock.Ransom.FileInfector.DDS
TrendMicro-HouseCallPE_VIRLOCK.I
RisingTrojan.Win32.PolyRansom.a (CLASSIC)
IkarusVirus.Win32.Virlock
MaxSecureVirus.PolyRansom.b
FortinetW32/Virlock.B
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom.VirLock.66?

Ransom.VirLock.66 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment