Virus

Virus:Win32/Virut.A malicious file

Malware Removal

The Virus:Win32/Virut.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Virut.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Virus:Win32/Virut.A?


File Info:

name: A1E42FC663D9F832836F.mlw
path: /opt/CAPEv2/storage/binaries/42fa4bcaaf03fcffac91837f54c437fef6c86b093bcf85c2b35cc48b515fd164
crc32: 5ACE52D5
md5: a1e42fc663d9f832836fd5f9816436f8
sha1: c1fe67723b44bd7bfa984bb0e544196d9dcf0c26
sha256: 42fa4bcaaf03fcffac91837f54c437fef6c86b093bcf85c2b35cc48b515fd164
sha512: ef1df1734e6df160f92e9e855b78178a452f581369a706a275fb9d305dee1f4e6e1f41bb514470bbb584c9fb5dec0d7f95f7ecad680c6e5f237cdd0660fe4ace
ssdeep: 768:MYuwqgY48mWxEgfXmBN0ldWxOFfXFQ30ABVvtpkwaKw3:MYwIWT+BqldWxUSESvtpk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11403BF82F85516C5D6E501348C42DE622221EC17C43461A8F7F2BB4EBEFAFD7E92521A
sha3_384: 0f35e96a21e7e46a029e5194e6acd438a557171c1e8c04094a3c1f81dd02f6c4c2b225b293f9af28466b71fe3bf5db4c
ep_bytes: e800000000558b5c24088b6c2404816c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Virus:Win32/Virut.A also known as:

BkavW32.FemaRub.PE
LionicVirus.Win32.Virut.kYKs
Elasticmalicious (moderate confidence)
MicroWorld-eScanWin32.Generic.5765
FireEyeGeneric.mg.a1e42fc663d9f832
CAT-QuickHealW32.Virut.F
SkyhighBehavesLike.Win32.Mydoom.nc
McAfeeW32/Virut.b.a
MalwarebytesMalware.AI.4200526705
ZillyaVirus.Virut.Win32.1
SangforVirus_Suspicious.Win32.Virut.b
K7AntiVirusVirus ( 00001b6b1 )
AlibabaVirus:Win32/Virut.03aeb2e0
K7GWVirus ( 00001b6b1 )
Cybereasonmalicious.663d9f
ArcabitWin32.Generic.5765
BaiduWin32.Virus.Virut.b
VirITWin32.Virut.A
SymantecW32.Virut.A
tehtrisGeneric.Malware
ESET-NOD32Win32/Virut.5127
APEXMalicious
TrendMicro-HouseCallPE_VIRUT.A
ClamAVWin.Trojan.Virut-14
KasperskyVirus.Win32.Virut.a
BitDefenderWin32.Generic.5765
NANO-AntivirusVirus.Win32.Virut.jxol
AvastWin32:Mydoom-H [Wrm]
TencentVirus.Win32.Virut.aa
TACHYONVirus/W32.Virut.Gen
SophosW32/Virut-T
F-SecureMalware.W32/Virut.Gen
DrWebWin32.Virut
VIPREWin32.Generic.5765
TrendMicroPE_VIRUT.A
Trapminesuspicious.low.ml.score
EmsisoftWin32.Generic.5765 (B)
IkarusEmail-Worm.Win32.Mydoom
JiangminWin32/Virut.a
GoogleDetected
AviraW32/Virut.Gen
VaristW32/Virut.4960
Antiy-AVLVirus/Win32.Virut.a
KingsoftWin32.Virut.a.8192
XcitiumBackdoor.Win32.Nepoe.em2@1d9dlz
MicrosoftVirus:Win32/Virut.A
ViRobotWin32.Virut.Gen.A
ZoneAlarmVirus.Win32.Virut.a
GDataWin32.Virus.Virut.D
CynetMalicious (score: 100)
AhnLab-V3Win32/Virut
VBA32Virus.Win32.Virut.A
ALYacWin32.Generic.5765
MAXmalware (ai score=100)
Cylanceunsafe
PandaW32/Virutas.B
ZonerProbably Heur.ExeHeaderL
RisingVirus.Virut!1.A08B (CLASSIC)
YandexTrojan.GenAsa!fSutCAXLtT8
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Virut
FortinetW32/Virut.A
BitDefenderThetaAI:FileInfector.1E3F74C612
AVGWin32:Mydoom-H [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)
alibabacloudVirus:Win/Virut.a

How to remove Virus:Win32/Virut.A?

Virus:Win32/Virut.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment