Virus

About “Virus:Win32/Virut.BM” infection

Malware Removal

The Virus:Win32/Virut.BM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Virut.BM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Virus:Win32/Virut.BM?


File Info:

crc32: 29F5C160
md5: cd498656c03ee18f96cb77b07b07bb90
name: WBF2ISO.exe
sha1: 57ad4238fa080bd4c79d0dcdda3b8510b534d9d6
sha256: 9d153b6f99fb78d8f6c8427c014defb4eb05d8bb44f60814b60821d38b376f90
sha512: eed6be76acec0c7b7fcb2bf895efac6108966134dbba92ecf6f279c76be0575d791c70d99e0d52e877433d8a6b44461ab50b46d491fd08882f1b9785ad5e0966
ssdeep: 24576:+Iy6KvES1dbt6Trz9L+PlqtP3lbp3GB5EY3bUjeqAZ1S:aES6T54oP3X2B5EYLUjuvS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1. 0. 0. 0
CompanyName: x7535x73a9x5df4x58eb
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 0.0.0.0
FileDescription: WBF2ISO
OriginalFilename:
Translation: 0x0409 0x04e4

Virus:Win32/Virut.BM also known as:

BkavW32.Vetor.PE
MicroWorld-eScanWin32.Virtob.Gen.12
FireEyeGeneric.mg.cd498656c03ee18f
CAT-QuickHealW32.Virut.G
Qihoo-360Win32/Virus.600
McAfeeW32/Virut.ad.gen
VIPREVirus.Win32.Virut.ce (v)
K7AntiVirusVirus ( f10002001 )
BitDefenderWin32.Virtob.Gen.12
K7GWVirus ( f10002001 )
Cybereasonmalicious.6c03ee
Invinceaheuristic
BitDefenderThetaAI:FileInfector.C9457D4313
F-ProtW32/Virut.AI!Generic
SymantecW32.Virut.CF
ESET-NOD32Win32/Virut.NBP
BaiduWin32.Virus.Virut.gen
TrendMicro-HouseCallPE_VIRUX.A-4
AvastWin32:Vitro
GDataWin32.Virtob.Gen.12
KasperskyVirus.Win32.Virut.ce
AlibabaVirus:Win32/Virut.c7d3e4a0
NANO-AntivirusVirus.Win32.Virut.hpeg
ViRobotWin32.Virut.Gen.C
APEXMalicious
TencentVirus.Win32.Virut.Gen.200009
SophosW32/Scribble-B
ComodoVirus.Win32.Virut.Ce@1fy3nv
F-SecureMalware.W32/Virut.Gen
DrWebWin32.Virut.56
TrendMicroPE_VIRUX.A-4
McAfee-GW-EditionW32/Virut.ad.gen
Trapminemalicious.moderate.ml.score
EmsisoftWin32.Virtob.Gen.12 (B)
SentinelOneDFI – Suspicious PE
CyrenW32/Virut.AI!Generic
JiangminWin32/Virut.bt
AviraW32/Virut.Gen
MAXmalware (ai score=88)
KingsoftWin32.Virut.nd.53248
ArcabitWin32.Virtob.Gen.12
AhnLab-V3Win32/Virut.E
ZoneAlarmVirus.Win32.Virut.ce
MicrosoftVirus:Win32/Virut.BM
TotalDefenseWin32/Virut.17408
Acronissuspicious
VBA32Virus.Virut.06
TACHYONVirus/W32.Virut.Gen
Ad-AwareWin32.Virtob.Gen.12
CylanceUnsafe
PandaW32/Sality.AO
RisingVirus.Virut!1.A08B (CLASSIC)
YandexWin32.Virut.Y.Gen
IkarusTrojan-Dropper.Win32.Clons
FortinetW32/Virut.CE
AVGWin32:Vitro
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureVirus.Virut.CE

How to remove Virus:Win32/Virut.BM?

Virus:Win32/Virut.BM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment