Virus

Virus:Win32/Viking.MK malicious file

Malware Removal

The Virus:Win32/Viking.MK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Viking.MK virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Viking.MK?


File Info:

name: 6BE8156F866216D38072.mlw
path: /opt/CAPEv2/storage/binaries/af3f546db84ddead58999ffac4101b6b33608607b0d02ff845f9cac9fcdb20a9
crc32: 4E6AEABA
md5: 6be8156f866216d38072055dcc1659bf
sha1: 941c4b151ffdae371d22cc73790866c25b1478b7
sha256: af3f546db84ddead58999ffac4101b6b33608607b0d02ff845f9cac9fcdb20a9
sha512: 55ea2748ad311f369dc168ea6aab077d40ca143bd24101ba099fbdb4da9afd05c2d600b5a6e388ac93d1c4500f266c3297ccb280d1d023acb1adb71e322536e2
ssdeep: 6144:DLZ/JdSuWb4zA9TSFem40nVl068HjeD9p/Q37wk1WUh44SmCldLn:Z/JEn8A9TSYm1HhBo7zIXzL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T113744B017B518EB6F5A28C7E1D6AA31D2A6ABD210F10D2D373606F4DCC321F59A3E356
sha3_384: ca30c34d4efbcb7059c055e00fd118c2aea1b5601f6fb562c5c96064de36103ad7e95f13128e03ac82153c941a0f2c7c
ep_bytes: b811d1cccabbebcf743503c38b00ffd0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Virus:Win32/Viking.MK also known as:

BkavW32.LogoOne.PE
LionicWorm.Win32.Viking.kYUj
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Legmir.504
MicroWorld-eScanGen:Variant.Strictor.271320
ClamAVWin.Trojan.Philis-1
CAT-QuickHealW32.Viking.H8
McAfeeW32/HLLP.q.q
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Viking.Win32.45
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaVirus:Win32/Viking.4d5c
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.5EF0A8031F
VirITWorm.Win32.Viking.AA
CyrenW32/DelfInject.A.gen!Eldorado
SymantecW32.Looked.H
tehtrisGeneric.Malware
ESET-NOD32Win32/Viking.NAC
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Viking.h
BitDefenderGen:Variant.Strictor.271320
NANO-AntivirusTrojan.Win32.Viking.bnapm
AvastWin32:Trojan-gen
TencentWorm.Win32.Viking.h
EmsisoftGen:Variant.Strictor.271320 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Virus.Agent.s
VIPREGen:Variant.Strictor.271320
TrendMicroPE_LOOKED.YH
McAfee-GW-EditionBehavesLike.Win32.HLLPPhilis.fh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.6be8156f866216d3
SophosW32/Looked-Gen
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Strictor.271320
JiangminWorm/Viking.f
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.Viking
XcitiumTrojWare.Win32.Magania.~AEA@f80tu
ArcabitTrojan.Strictor.D423D8
ZoneAlarmWorm.Win32.Viking.h
MicrosoftVirus:Win32/Viking.MK
GoogleDetected
AhnLab-V3Win32/Viking.DK
Acronissuspicious
VBA32Win32.Virus.Unknown.Heur
ALYacGen:Variant.Strictor.271320
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPE_LOOKED.YH
RisingWorm.Viking.ac (CLASSIC)
YandexWorm.Viking.K
IkarusWorm.Win32.Delf
MaxSecureTrojan.Malware.602566.susgen
FortinetW32/Viking.H
AVGWin32:Trojan-gen
Cybereasonmalicious.51ffda
DeepInstinctMALICIOUS

How to remove Virus:Win32/Viking.MK?

Virus:Win32/Viking.MK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment