Malware

Win32.Virlock.A information

Malware Removal

The Win32.Virlock.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Virlock.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32.Virlock.A?


File Info:

name: 043993231B032B2C29D4.mlw
path: /opt/CAPEv2/storage/binaries/423863f68dd9137736a7de11b09e2f57a624322617c688d2ff3f593033f0df6e
crc32: 2B56E6FD
md5: 043993231b032b2c29d450e900c56048
sha1: 68aa0c4e7006dfd4aadc8a4cc2a1eba04cdb9d50
sha256: 423863f68dd9137736a7de11b09e2f57a624322617c688d2ff3f593033f0df6e
sha512: 55673e51ca45c2d8687acc888fe8c7c6266ac28b1d2e509aeb5d322594797c5814d6b894e8a706f8c00746540c4ff2e6d682b2138161597650798a4e36d1f8d5
ssdeep: 3072:6H2AI6DCPda0XCfpmLtwkHXfLJxFk7tvX6X+6M9Cl/JOHioYp:6WCDAXCRKHXvFqtyXVM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1E312164A915944C7700EB701818CB5AB02F8753B7E27368981BEB7BA740E5FF742DE
sha3_384: 0fae18e345094b72a14409fba04273a58ea9e4ef8f3a5d80d592d2736834c69bfbf2fa93c3b9fde2ccae496cfe2c6e50
ep_bytes: 60be001041008dbe0000ffff5783cdff
timestamp: 1970-01-01 00:02:03

Version Info:

0: [No Data]

Win32.Virlock.A also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Virlock.n!c
tehtrisGeneric.Malware
MicroWorld-eScanWin32.Virlock.A
FireEyeGeneric.mg.043993231b032b2c
SkyhighBehavesLike.Win32.Generic.cc
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 0040f99f1 )
K7GWVirus ( 0040f99f1 )
Cybereasonmalicious.31b032
BitDefenderThetaAI:FileInfector.1F8DFD280F
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Virlock.D
TrendMicro-HouseCallPE_VIRLOCK.F
ClamAVBC.Win.Virus.Ransom-9157.A
KasperskyVirus.Win32.PolyRansom.a
BitDefenderWin32.Virlock.A
NANO-AntivirusTrojan.Win32.PolyRansom.exypia
AvastWin32:VirLock-A
EmsisoftWin32.Virlock.A (B)
F-SecureHeuristic.HEUR/AGEN.1348321
VIPREWin32.Virlock.A
TrendMicroPE_VIRLOCK.F
Trapminemalicious.high.ml.score
SophosW32/VirRnsm-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
GoogleDetected
AviraHEUR/AGEN.1348321
VaristW32/S-27bc0672!Eldorado
MicrosoftVirus:Win32/Nabucur.A
ArcabitWin32.Virlock.A
ZoneAlarmVirus.Win32.PolyRansom.a
GDataWin32.Virlock.A
CynetMalicious (score: 100)
AhnLab-V3Win32/Nabucur
Acronissuspicious
VBA32Virus.VirLock
ALYacWin32.Virlock.A
TACHYONVirus/W32.VirRansom.C
Cylanceunsafe
RisingVirus.VirLock!1.A08A (CLASSIC)
YandexVirus.Virlock.Gen.AAJ
IkarusVirlock.Win32
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Virlock.K
AVGWin32:VirLock-A
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)
alibabacloudVirus:Win/Virlock.D

How to remove Win32.Virlock.A?

Win32.Virlock.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment