Malware

About “Win32/Virlock.F” infection

Malware Removal

The Win32/Virlock.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Virlock.F virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Virlock.F?


File Info:

name: 54DBC7FCE6C6EFA8AC05.mlw
path: /opt/CAPEv2/storage/binaries/fad96aedf8f7574ef1e00019837ad3172abdabcce28851610dafd2d9d838b737
crc32: 5949050E
md5: 54dbc7fce6c6efa8ac059c0f01e26b3b
sha1: e06270950ecad8c42777151b0903c0ccda8acb2d
sha256: fad96aedf8f7574ef1e00019837ad3172abdabcce28851610dafd2d9d838b737
sha512: 3c8ae9003f71a4619da20dc2580eeb81c243eeda0c6f63b886956de4e4f0e711e35d9c9b76db93caf6f8b168dc201d4d7c1513d3318339914e58c0ddc7281164
ssdeep: 12288:SltZdlf/wA0vTJ7/6OYCeMfCA83kWmiuvcTgWfoeckZECRbL7O3QwW4GdJZD:cdlZ6TJ7/6OZfCdkuhUdkiuPmQDdJZD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16775CD62110CDE8ACC06143724ABED968ABB7AF425EC313D9D710249FB74BBA1D51E3D
sha3_384: 0e2aa2134f9c071739594c14130cd7ef7c6e07afe947ac8a22398ddda3562ca306ff884e714990bfe8649fa2d32ca17b
ep_bytes: 87fbc1c90523d62bc28bca87da81efed
timestamp: 2024-01-25 14:31:07

Version Info:

0: [No Data]

Win32/Virlock.F also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Virlock.Gen.5
CAT-QuickHealRansom.PolyRansom.B2
SkyhighBehavesLike.Win32.VirRansom.tc
McAfeeW32/VirRansom
MalwarebytesTrojan.VirLock
ZillyaVirus.PolyRansom.Win32.2
SangforRansom.Win32.Save.a
K7AntiVirusVirus ( 0040f99f1 )
K7GWVirus ( 0040f99f1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Virlock.Gen.5
BaiduWin32.Virus.Virlock.a
VirITWin32.CryptorGen.A
SymantecW32.Virlock
tehtrisGeneric.Malware
ESET-NOD32Win32/Virlock.F
CynetMalicious (score: 100)
APEXMalicious
ClamAVBC.Win.Virus.Ransom-9157.B
KasperskyVirus.Win32.PolyRansom.a
BitDefenderWin32.Virlock.Gen.5
NANO-AntivirusTrojan.Win32.PolyRansom.exypia
AvastWin32:VirLock [Inf]
TencentVirus.Win32.Polyransom.a
TACHYONVirus/W32.VirRansom.C
EmsisoftWin32.Virlock.Gen.5 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebWin32.VirLock.4
VIPREWin32.Virlock.Gen.5
TrendMicroPE_VIRLOCK.E-O
FireEyeGeneric.mg.54dbc7fce6c6efa8
SophosW32/VirRnsm-A
IkarusWin32.Cryptor
VaristW32/S-85d93908!Eldorado
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLVirus/Win32.PolyRansom.a
XcitiumPacked.Win32.Graybird.B@5hgpd5
MicrosoftTrojan:Win32/NabucurObfs
ZoneAlarmVirus.Win32.PolyRansom.a
GDataWin32.Virlock.Gen.5
GoogleDetected
AhnLab-V3Win32/Nabucur.B
Acronissuspicious
BitDefenderThetaAI:FileInfector.47FA551513
ALYacWin32.Virlock.Gen.5
MAXmalware (ai score=81)
VBA32BScope.Trojan.Fuerboos
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallPE_VIRLOCK.E-O
RisingVirus.VirLock!1.A08A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.PolyRansom.a
FortinetW32/Virlock.E
AVGWin32:VirLock [Inf]
Cybereasonmalicious.50ecad
DeepInstinctMALICIOUS

How to remove Win32/Virlock.F?

Win32/Virlock.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment