Malware

How to remove “Win32/Virut.NEY”?

Malware Removal

The Win32/Virut.NEY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Virut.NEY virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Virut.NEY?


File Info:

name: 490757D49968F8192556.mlw
path: /opt/CAPEv2/storage/binaries/bfe5b2a620c85d83ef29c080e43f38489a761ec41417da90722e0fd1cc14c911
crc32: 3CAF1C5B
md5: 490757d49968f81925565d7f2e283c09
sha1: 533962e92e57f52de6ec99dc651d687ccd84911b
sha256: bfe5b2a620c85d83ef29c080e43f38489a761ec41417da90722e0fd1cc14c911
sha512: 8d1ccd89823f4504769025c742f371bcb0d8a5e7d1e26ff326610c2ae32c8c754d28e820fba7f887f1b762af9b4278624610499fcd004e43bc66a1196c0314d0
ssdeep: 1536:vkq6X6S6RdTWMpFIMusEzMZwnwFRBbwCKSE8aWvI/Za2cc:vla6S6RMMfosEzMZEmJzaWmZv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187B35A0063E4553AF1F2667859BD56715A3EFC513739E68F1240C28E8A26FC0AF3936B
sha3_384: 0688b7b8198c3e9a3c1f5a0cfab0428ce4db92a9925de45e152cadfb3863f5cb17c74c6d4b2e1d1e3fe6221e0749d643
ep_bytes: 6a6068001e0001e874180000bf940000
timestamp: 2004-08-04 05:59:22

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Internet Connection Wizard
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: ICWCONN2
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: ICWCONN2.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.00.2900.2180
Translation: 0x0409 0x04b0

Win32/Virut.NEY also known as:

BkavW32.Vetor.PE
LionicVirus.Win32.Virut.n!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.490757d49968f819
CAT-QuickHealW32.Virut.G
SkyhighBehavesLike.Win32.Generic.ch
McAfeeArtemis!490757D49968
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( f10002001 )
AlibabaVirus:Win32/Virut.2ddced9f
K7GWVirus ( f10002001 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITWin32.Scribble.Q
SymantecW32.Virut.CF
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Virut.NEY
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Virut.ce
NANO-AntivirusVirus.Win32.Virut.hpeg
AvastWin32:Virtu-I [Inf]
RisingVirus.Virut!1.A08B (CLASSIC)
SophosW32/Scribble-B
F-SecureTrojan.TR/Patched.Ren.Gen
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
JiangminWin32/Virut.bt
VaristW32/Virut.CE.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLVirus/Win32.Virut.ce
Kingsoftmalware.kb.a.998
MicrosoftVirus:Win32/Virut.BN
XcitiumVirus.Win32.Virut.CE@5jedjj
ZoneAlarmVirus.Win32.Virut.ce
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.hq0@aSzCYpni
VBA32Virus.Virut.02
Cylanceunsafe
PandaW32/Sality.AO
TencentVirus.Win32.Virut.CE.200087
IkarusVirus.Win32.Virut
MaxSecureVirus.Virut.CE
FortinetW32/Virut.NEY
AVGWin32:Virtu-I [Inf]
DeepInstinctMALICIOUS

How to remove Win32/Virut.NEY?

Win32/Virut.NEY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment