Virus

Virus:Win32/Viking.NF information

Malware Removal

The Virus:Win32/Viking.NF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Viking.NF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with NsPack
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Viking.NF?


File Info:

name: 9E92EE909D26C0DD2823.mlw
path: /opt/CAPEv2/storage/binaries/88cdd5015f0bc91e7159fe165ae591020095635e1c2819f0b23d22a606f769bb
crc32: B8D710C7
md5: 9e92ee909d26c0dd28235c8f94d122b1
sha1: 12a33a80a1569c97f7981549705d5e7d900b48da
sha256: 88cdd5015f0bc91e7159fe165ae591020095635e1c2819f0b23d22a606f769bb
sha512: d5df2e3e845224b32c5a0abe62fa95aebd84e617a7b7be1a3a21a003aa09e2ddab4a2b3c5fea4db0989e4edb704593b58f6b4f2d70cf98cf4f4322a6a45cc633
ssdeep: 1536:W32D306WeCUlnRjIudrE53bxL8RfjYzbZg5uqV3oesc6sKuWk7F:W3YE69JIao5rxC7DKuj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15383020EC1E116C9F6DF497E078283BD37196C0CED8EF02BDD0494C5DD82649668ABEA
sha3_384: ee2710df9a8965a41653fddf64d430019ba8a491e94efdc9dae303efc770f97fa0e3708bdc696d9e685c06bb5636fcb3
ep_bytes: 9c60e8000000005d83ed078d9d81fcff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Virus:Win32/Viking.NF also known as:

BkavW32.OverLeyAG.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Fujacks.PRP.DG
ClamAVWin.Trojan.Pakes-2501
FireEyeGeneric.mg.9e92ee909d26c0dd
CAT-QuickHealWorm.Fujack.DG3
ALYacWin32.Fujacks.PRP.DG
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Fujacks.PRP.DG
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 000a15661 )
K7GWTrojan ( 000a15661 )
Cybereasonmalicious.09d26c
BaiduWin32.Worm.BMW.c
VirITTrojan.Win32.Pakes.NKM
CyrenW32/Fujack.PBDT-2061
SymantecW32.Fujacks.CA
tehtrisGeneric.Malware
ESET-NOD32Win32/Fujacks.BK
ZonerProbably Heur.ExeHeaderP
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Fujack.df
BitDefenderWin32.Fujacks.PRP.DG
NANO-AntivirusTrojan.Win32.Pakes.dmkxin
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.BMW.ta
TACHYONTrojan/W32.Packer.82439.B
EmsisoftWin32.Fujacks.PRP.DG (B)
F-SecureMalware.W32/Crypt.APK
DrWebWin32.HLLP.Whboy.113
ZillyaWorm.Fujack.Win32.1231
TrendMicroPE_FUJACKS.DE-O
McAfee-GW-EditionBehavesLike.Win32.ExploitMydoom.mc
Trapminemalicious.moderate.ml.score
SophosW32/Fujacks-BD
IkarusNet-Worm.Win32.Agent
GDataWin32.Fujacks.PRP.DG
JiangminTrojan/Pakes.gps
AviraW32/Crypt.APK
Antiy-AVLWorm/Win32.Fujack.df
XcitiumTrojWare.Win32.Trojan.NSPM.~gen@20n73t
ArcabitWin32.Fujacks.PRP.DG
ViRobotTrojan.Win32.Pakes.82439.B
ZoneAlarmWorm.Win32.Fujack.df
MicrosoftVirus:Win32/Viking.NF
GoogleDetected
AhnLab-V3Worm/Win32.Fujack.R1891
Acronissuspicious
McAfeeW32/Fujacks.ax.aw
MAXmalware (ai score=89)
VBA32Virus.Viking.3109
Cylanceunsafe
PandaW32/Radoppan.AT.worm
TrendMicro-HouseCallPE_FUJACKS.DE-O
RisingWin32.BMW.ba (CLASSIC)
YandexTrojan.GenAsa!f2rrsjMqUXc
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Fujack.DF
FortinetW32/Fujacks.DE
BitDefenderThetaAI:FileInfector.2915C65D14
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Viking.NF?

Virus:Win32/Viking.NF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment