Virus

How to remove “Virus:Win32/Virut.AC”?

Malware Removal

The Virus:Win32/Virut.AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Virut.AC virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Virus:Win32/Virut.AC?


File Info:

name: F6AA43C02FED8DEB0F21.mlw
path: /opt/CAPEv2/storage/binaries/74e7215f8536034c00853596947ba714f24a8044f8f23d4a0675e1f32fa3a9e5
crc32: 02DE6883
md5: f6aa43c02fed8deb0f213a568bb90b06
sha1: 8498bdba1bd01db018d19e71fd860e006be260fb
sha256: 74e7215f8536034c00853596947ba714f24a8044f8f23d4a0675e1f32fa3a9e5
sha512: fd137d1f4ca80480cc58352512c2d65a0be85631ba825ab4a25a5372386428cf7ac52f1617c00db3b10b18c26eba9b0dc092a396bd415f485642e82b90398f2d
ssdeep: 6144:GAza2p1jQQ+QeewQeeNQeesQee0fQeefQeeKqz6pJs1I8qMBY8C0IMNufQTg:GMaAtz6pJCyJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B540701A3F8851AF0F33B746D7D66A66A3ABC219934C28E6390712F5E70BD58971723
sha3_384: d5d6729051a7952d8f4516b5f28f5dfd57bb7ce11f3d9a428f140d861f1ba046d8b2735b847cd9f4985c587ba8f3775c
ep_bytes: fce82800000053b9a50d00008bda6631
timestamp: 2003-10-07 00:42:36

Version Info:

CompanyName: NVIDIA Corporation
FileDescription: NVIDIA nView Control Panel, Version 52.16
FileVersion: 6.14.10.5216
InternalName: KEYSTONE
LegalCopyright: (C) NVIDIA Corporation. All rights reserved.
OriginalFilename: keystone.exe
ProductName: NVIDIA nView Control Panel, Version 52.16
ProductVersion: 6.14.10.5216
Translation: 0x0409 0x04e2

Virus:Win32/Virut.AC also known as:

BkavW32.VtLikeB.PE
Elasticmalicious (high confidence)
DrWebWin32.Virut.30
MicroWorld-eScanWin32.Virtob.8.Gen
FireEyeGeneric.mg.f6aa43c02fed8deb
CAT-QuickHealW32.Virut.E
SkyhighBehavesLike.Win32.Virut.dh
ALYacWin32.Virtob.8.Gen
Cylanceunsafe
VIPREWin32.Virtob.8.Gen
K7AntiVirusVirus ( 00001b781 )
K7GWVirus ( 00001b781 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:FileInfector.A10FCAA712
VirITWin32.Virut.AV
SymantecW32.Virut.W
ESET-NOD32Win32/Virut.AV
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Virut.av
BitDefenderWin32.Virtob.8.Gen
NANO-AntivirusVirus.Win32.Virut.ljfw
AvastWin32:Virtob [Inf]
TencentVirus.Win32.Virut.b
TACHYONVirus/W32.Virut.Gen
EmsisoftWin32.Virtob.8.Gen (B)
F-SecureMalware.W32/Virut.AX
BaiduWin32.Virus.Virut.b
ZillyaVirus.Virut.Win32.24
TrendMicroPE_VIRUT.AV
SophosW32/Virut-W
IkarusVirus.Virut
GDataWin32.Virus.Virut.T
JiangminWin32/Virut.af
WebrootW32.Virut.Gen
GoogleDetected
AviraW32/Virut.AX
Antiy-AVLVirus/Win32.Virut.av
KingsoftWin32.Virut.xf.57344
XcitiumVirus.Win32.Virut.AV@f7xjw
ArcabitWin32.Virtob.8.Gen
ViRobotWin32.Virut.S
ZoneAlarmVirus.Win32.Virut.av
MicrosoftVirus:Win32/Virut.AC
VaristW32/Virut.7116
AhnLab-V3Win32/Virut.B
VBA32Virus.Virut.07
MAXmalware (ai score=86)
PandaGeneric Malware
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPE_VIRUT.AV
RisingWin32.Virut.an (CLASSIC)
YandexWin32.Virut.Gen.4
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Virut.CE
FortinetW32/Virut.J
AVGWin32:Virtob [Inf]
Cybereasonmalicious.a1bd01

How to remove Virus:Win32/Virut.AC?

Virus:Win32/Virut.AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment