Virus

Virus.VirLock.1190A removal guide

Malware Removal

The Virus.VirLock.1190A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.VirLock.1190A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus.VirLock.1190A?


File Info:

name: 16D8798293F8CCB07FB7.mlw
path: /opt/CAPEv2/storage/binaries/fec9b1a74b26583ef8ca4ac5d0445bb946db8a46b1ac5a7d4f4442e06db38277
crc32: E4505139
md5: 16d8798293f8ccb07fb707e0c241bc75
sha1: 533f78452185cbf1a250c14dec050f0409561b8a
sha256: fec9b1a74b26583ef8ca4ac5d0445bb946db8a46b1ac5a7d4f4442e06db38277
sha512: f6b4899de9c141d3f6bebcf18ee22a309af3e8d0766e78a36c2f6bf89017d6b9ab241589e0311f5f05c7deb1bdb87581152b46671e2408a043f19b3e44c43fd0
ssdeep: 12288:78AFTsWbtjKEsJd/WMhdXK0jjjAf/GXLKQc/bQcrBQceqZWaQcocwQcBLAT7e4aw:4AFIWJt4Q4d/Mf/GXLKQc/bQcrBQceqL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1149402946F6C4FA2D0F9AD7981F55FECEDA6D582A0DD90CFC2309E385F0680113A265E
sha3_384: 2f9d43eda2721c168d7f1ad39fb02d0a41bca185d4dc7ce5299b7abbbe90e14e9366184abcdedc65794ecb4de2b36bf2
ep_bytes: e83dbf06003df4feffff0f8565000000
timestamp: 2015-01-06 00:36:08

Version Info:

0: [No Data]

Virus.VirLock.1190A also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.PolyRansom.mfPW
tehtrisGeneric.Malware
DrWebWin32.VirLock.10
MicroWorld-eScanWin32.Virlock.Gen.1
FireEyeGeneric.mg.16d8798293f8ccb0
McAfeeW32/VirRansom.b!16D8798293F8
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005662d71 )
AlibabaRansom:Win32/PolyRansom.cb1cdeb9
K7GWVirus ( 005662d71 )
Cybereasonmalicious.293f8c
ArcabitWin32.Virlock.Gen.1
BitDefenderThetaAI:FileInfector.4097910C13
VirITWin32.PolyRansom.B
CyrenW32/Virlock.N.gen!Eldorado
SymantecW32.Virlock!gen4
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Virlock.AL
TrendMicro-HouseCallPE_VIRLOCK.D-O
Paloaltogeneric.ml
ClamAVWin.Virus.Virlock-6804475-0
KasperskyVirus.Win32.PolyRansom.b
BitDefenderWin32.Virlock.Gen.1
NANO-AntivirusTrojan.Win32.Gena.doticp
AvastWin32:SwPatch [Wrm]
TencentVirus.Win32.Polyransom.b
Ad-AwareWin32.Virlock.Gen.1
EmsisoftWin32.Virlock.Gen.1 (B)
ComodoTrojWare.Win32.Virlock.XU@5xaovq
ZillyaVirus.Virlock.Win32.1
TrendMicroPE_VIRLOCK.D-O
McAfee-GW-EditionBehavesLike.Win32.VirRansom.gc
SophosML/PE-A + W32/VirRnsm-C
IkarusVirus.Win32.Virlock
JiangminWin32/Polyransom.b
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=86)
MicrosoftRansom:Win32/ContiCrypt.LOD!MTB
ZoneAlarmVirus.Win32.PolyRansom.b
GDataWin32.Virlock.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Win32/Nabucur.C.X1543
VBA32Virus.VirLock.1190A
ALYacWin32.Virlock.Gen.1
TACHYONVirus/W32.VirRansom
MalwarebytesTrojan.VirLock
APEXMalicious
RisingTrojan.Generic@AI.100 (RDMK:cmRtazr+qf0zRl12NxGy21mOhueb)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.PolyRansom.b
FortinetW32/Virlock.D
AVGWin32:SwPatch [Wrm]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus.VirLock.1190A?

Virus.VirLock.1190A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment