Ransom

Should I remove “Ransom.VirLock.85”?

Malware Removal

The Ransom.VirLock.85 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.VirLock.85 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.VirLock.85?


File Info:

name: D4B6241ABCEEB9CB22F9.mlw
path: /opt/CAPEv2/storage/binaries/110571a60a5d07607d0462a97b8aa4b64321c2e723d6e4854357a7d2a228ffa9
crc32: F05E9066
md5: d4b6241abceeb9cb22f9abb74ef4f282
sha1: a5fc1ef64d2975594f68ab2237d34aa720929ee3
sha256: 110571a60a5d07607d0462a97b8aa4b64321c2e723d6e4854357a7d2a228ffa9
sha512: f24352e42d55e9e72ae84fbf79697f05c6c3be01cf0936a01f77573b9ebaca7339ec8c834b67eb9be6cf44327e3eb6e8ae9420f34f11f9f6fd1298cef1dc1a88
ssdeep: 3072:DjZfPD318CFlLsjuhwZlNmA8g74rM+7VzcrUixmWibizAvlfYkmhAUPnl8YMx4:HZfL31h19IJxmWibizARfmP8v4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA44E26ACBEDBDE6CD354170F3E39987764DCF2B55970A0702261B345EACE30603968A
sha3_384: 0e7cdd7a9d37a78ede9cf07d6f74ea47f3730ff67c8d58b3b8bd6f2264f6dce0f0ec6425438505e85689057819272d38
ep_bytes: b9b3560b00bad9dd0d0081e9a6960d00
timestamp: 1970-01-01 00:02:03

Version Info:

0: [No Data]

Ransom.VirLock.85 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.VirLock.2
MicroWorld-eScanGen:Variant.Ransom.VirLock.85
SkyhighBehavesLike.Win32.VirRansom.dc
McAfeeW32/VirRansom
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.PolyRansom.Win32.1
SangforRansom.Win32.Save.a
K7AntiVirusVirus ( 0040f99f1 )
K7GWVirus ( 0040f99f1 )
Cybereasonmalicious.64d297
ArcabitTrojan.Ransom.VirLock.85
BitDefenderThetaGen:NN.ZexaF.36680.piW@aSQ3Gybi
VirITWin32.CryptorGen.B
SymantecW32.Virlock!inf
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Virlock.D
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.PolyRansom.a
BitDefenderGen:Variant.Ransom.VirLock.85
NANO-AntivirusTrojan.Win32.Kryptik.dmrlkh
AvastWin32:VirLock [Inf]
TencentVirus.Win32.VirLocker.b
EmsisoftGen:Variant.Ransom.VirLock.85 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Virus.Virlock.a
VIPREGen:Variant.Ransom.VirLock.85
TrendMicroPE_VIRLOCK.C
SophosW32/VirRnsm-A
IkarusVirus-Ransom.FileLocker
JiangminWin32/Polyransom.a
VaristW32/S-27bc0672!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLVirus/Win32.PolyRansom.a
XcitiumPacked.Win32.Graybird.B@5hgpd5
MicrosoftVirus:Win32/Nabucur.A
ZoneAlarmVirus.Win32.PolyRansom.a
GDataGen:Variant.Ransom.VirLock.85
GoogleDetected
Acronissuspicious
VBA32Virus.VirLock
ALYacGen:Variant.Ransom.VirLock.85
TACHYONVirus/W32.VirRansom.C
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPE_VIRLOCK.C
RisingTrojan.Woreflint!8.F5EA (TFE:2:uCpAlr7fINI)
YandexVirus.Virlock.Gen.AAJ
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.PolyRansom.a
FortinetW32/Virlock.K
AVGWin32:VirLock [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom.VirLock.85?

Ransom.VirLock.85 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment