Categories: Virus

Virus:Win32/Virut.AE removal instruction

The Virus:Win32/Virut.AE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Virut.AE virus can do?

  • Unconventionial language used in binary resources: Catalan
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Virus:Win32/Virut.AE?


File Info:

name: 1467C1CE621EF4C39069.mlwpath: /opt/CAPEv2/storage/binaries/f362851dce5f36705b2e6e2cde95a8cb7c588f4c38702775a7fbc193f3744028crc32: 9BB8F258md5: 1467c1ce621ef4c390693c4229bc8329sha1: 9c7fb1b2caf07696d29e9abbf7d1ae7d453ae673sha256: f362851dce5f36705b2e6e2cde95a8cb7c588f4c38702775a7fbc193f3744028sha512: d4a5194a942528873e6a7200c06d632b34c451a5fd307bca616b7168d2f0e7836513195b983f196e370d504e915345321d385b9c3e940b31b6293af86408dcbessdeep: 1536:nR0vxn3Pc0LCH9MtbvabUDzJYWu3BAq2iZYI02h:nR2xn3k0CdM1vabyzJYWqNFYI02htype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T164E3E14AB974A6DEF769CA368448FF445A34BD690EF3C6B6344C318E9B39C814A9431Csha3_384: 869cd4edf51a2bec2b500cc8dcfe97b6b610211741a740b957d9552b7bd276506ce44ef902e3f34b7ecc1324c7b7f570ep_bytes: f9558bece816000000f9f5e8b1000000timestamp: 2055-05-25 18:10:40

Version Info:

CompanyName: Macromedia, Inc.FileDescription: Macromedia Flash Player 7.0 r19FileVersion: 7,0,19,0InternalName: Macromedia Flash Player 7.0LegalCopyright: Copyright © 1996-2003 Macromedia, Inc.LegalTrademarks: Macromedia Flash PlayerOriginalFilename: SAFlashPlayer.exeProductName: Shockwave FlashProductVersion: 7,0,19,0Translation: 0x0409 0x04b0

Virus:Win32/Virut.AE also known as:

Bkav W32.Vetor.PE
Elastic malicious (high confidence)
DrWeb Win32.Virut.5
MicroWorld-eScan Win32.Virtob.4.Gen
FireEye Generic.mg.1467c1ce621ef4c3
CAT-QuickHeal W32.Virut.D
ALYac Win32.Virtob.4.Gen
Cylance Unsafe
VIPRE Win32.Virtob.4.Gen
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Virus ( 00001b761 )
K7GW Virus ( 00001b761 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta AI:FileInfector.64FF27A612
VirIT Win32.Cheburgen.A
Cyren W32/Ramnit.F.gen!Eldorado
Symantec Packed.Protexor!gen1
tehtris Generic.Malware
ESET-NOD32 Win32/Virut.U
APEX Malicious
TrendMicro-HouseCall PE_VIRUT.XS-4
Paloalto generic.ml
ClamAV Win.Trojan.Virut-41
Kaspersky Virus.Win32.Virut.q
BitDefender Win32.Virtob.4.Gen
NANO-Antivirus Virus.Win32.Virut.jxol
SUPERAntiSpyware Trojan.Agent/Gen-Pune
Avast Win32:Virut [Inf]
Tencent Trojan.Win32.Koobface.udb
Ad-Aware Win32.Virtob.4.Gen
Emsisoft Win32.Virtob.4.Gen (B)
Comodo Virus.Win32.Virut.q@1fhkey
Baidu Win32.Virus.Virut.i
Zillya Virus.Virut.Win32.14
TrendMicro PE_VIRUT.XS-4
McAfee-GW-Edition BehavesLike.Win32.Tupym.cm
Trapmine malicious.high.ml.score
Sophos ML/PE-A + W32/Vetor-A
SentinelOne Static AI – Malicious PE
Jiangmin Win32/Virut.f
Google Detected
Avira W32/Virut.V
MAX malware (ai score=89)
Antiy-AVL Trojan/Generic.ASVirus.14B
Microsoft Virus:Win32/Virut.AE
ViRobot Win32.Virut.Gen.B
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Win32.Virtob.4.Gen
Cynet Malicious (score: 100)
AhnLab-V3 Win32/Virut.D
McAfee PWS-Zbot.gen.cn
VBA32 Virus.Virut.07
Malwarebytes Nimnul.Virus.FileInfector.DDS
Rising Virus.Virut!1.A08C (CLASSIC)
Yandex Trojan.GenAsa!MLownxgq9A8
Ikarus Virus.Win32.Ramnit
Fortinet W32/Virut.fam
AVG Win32:Virut [Inf]
Cybereason malicious.e621ef
Panda W32/Virutas.gen

How to remove Virus:Win32/Virut.AE?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Genie.474 (B) (file analysis)

The Genie.474 (B) is considered dangerous by lots of security experts. When this infection is…

51 mins ago

About “Zusy.499310” infection

The Zusy.499310 is considered dangerous by lots of security experts. When this infection is active,…

56 mins ago

Malware.AI.1144596967 removal guide

The Malware.AI.1144596967 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32:VB-ABAN [Trj] (file analysis)

The Win32:VB-ABAN [Trj] is considered dangerous by lots of security experts. When this infection is…

1 hour ago

Generic.Dacic.94CCEEA9.A.568D4573 removal guide

The Generic.Dacic.94CCEEA9.A.568D4573 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.1459056935 removal instruction

The Malware.AI.1459056935 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago