Virus

What is “Virus:Win32/Zori.A”?

Malware Removal

The Virus:Win32/Zori.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Zori.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Virus:Win32/Zori.A?


File Info:

crc32: A0468C58
md5: c97c1f2192445918188f9bbf2e1fe3d0
name: C97C1F2192445918188F9BBF2E1FE3D0.mlw
sha1: f46386e3ef46337025372395fc8cba1d8db97d82
sha256: 3118a72538a6f4df80ba03066922e273e5a6cce7cd49638545fe53f2a06e957c
sha512: 3716d4283925534924fa72e6e32ede587dc81e5dc0b4f4bd10cc027809932f1d829d7d4023d4eecf4acb3c3b1ed07981346e7fe83178a846685e1e4690c7816f
ssdeep: 6144:LQe7WgQM6YT9Wka9YeUAva+POV1eRnCO:vaIH9WkamL8aC4QC
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Virus:Win32/Zori.A also known as:

BkavW32.AIDetect.malware2
LionicVirus.Win32.Zori.n!c
Elasticmalicious (high confidence)
DrWebWin32.HLLP.Death
CynetMalicious (score: 100)
CAT-QuickHealW32.Zori.A3
ALYacWin32.HLLP.Zori.A
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanDropper:Win32/dropper.ali1003001
Cybereasonmalicious.192445
SymantecW32.Zori.A
ESET-NOD32Win32/Zori.A
APEXMalicious
AvastFileRepMalware
KasperskyVirus.Win32.Zori.a
BitDefenderWin32.HLLP.Zori.A
NANO-AntivirusVirus.Win32.Zori.fsyf
MicroWorld-eScanWin32.HLLP.Zori.A
TencentVirus.Win32.Zori.as
Ad-AwareWin32.HLLP.Zori.A
SophosW32/Zori-A
ComodoWin32.Zori.A@2ak2
BitDefenderThetaGen:NN.ZelphiF.34142.AiZfa0Tuydbc
VIPREVirus.Win32.Zori.a (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.gz
FireEyeGeneric.mg.c97c1f2192445918
EmsisoftWin32.HLLP.Zori.A (B)
SentinelOneStatic AI – Malicious PE
AviraW32/Zori.A
MicrosoftVirus:Win32/Zori.A
ArcabitWin32.HLLP.Zori.A
GDataWin32.HLLP.Zori.A
McAfeeArtemis!C97C1F219244
MAXmalware (ai score=80)
PandaGeneric Suspicious
IkarusTrojan-Banker.Win32.Banbra
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zori.A
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Virus:Win32/Zori.A?

Virus:Win32/Zori.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment