Malware

Win32/Virut.O removal

Malware Removal

The Win32/Virut.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Virut.O virus can do?

  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Win32/Virut.O?


File Info:

name: 786711030504AEBEAABA.mlw
path: /opt/CAPEv2/storage/binaries/485bb98ec9454ef36625ac5e32e4e0f3e71fcadc30d3537ad57542e51a6f66b3
crc32: 0F4227CA
md5: 786711030504aebeaaba8d7181ac1da8
sha1: 6313f36c13acf8efac2ae02625625d971cfe9cdb
sha256: 485bb98ec9454ef36625ac5e32e4e0f3e71fcadc30d3537ad57542e51a6f66b3
sha512: 2dd862a31927b89653b01d3aa7c5a737e8a7d5897cd20babb43eb8534d01f59b51a024ff2b91dc3bc246c0836e1cb49ddb4ef08ede97e815d3d3f2281f44ce5c
ssdeep: 1536:AkphLgf3rZT2SGHIK4EpU1VebDObRCc3yFVQ0QaeC/BmXd1e4ijp:x8xRGH/K1sbSbR7yF20Q+BQ1e4it
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F9938D1262C49135E4F21AB05ABD23505B7EB9304F25AFDF929649DD48A8FC1CA30FB7
sha3_384: 34b51407701bf0b81d4cbfe38017dc8143b146c67e84ee7e880e92d68f304c9b4c1f0e9de2e25bb4fce06545ba1e42de
ep_bytes: 90fc90eb0060558bece813000000f8f9
timestamp: 2055-05-25 18:10:40

Version Info:

CompanyName: Microsoft Corporation
FileDescription: LZ Expansion Utility
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: expand
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: expand
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Win32/Virut.O also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.Virut.n!c
Elasticmalicious (high confidence)
DrWebWin32.Virut.5
MicroWorld-eScanTrojan.GenericKD.47495963
FireEyeGeneric.mg.786711030504aebe
CAT-QuickHealW32.Virut.D
McAfeeW32/Virut.rem.E
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00001b761 )
AlibabaVirus:Win32/Virut.a9972985
Cybereasonmalicious.c13acf
CyrenW32/Virut.AJ
ESET-NOD32Win32/Virut.O
APEXMalicious
ClamAVWin.Trojan.Virut-35
KasperskyVirus.Win32.Virut.q
BitDefenderTrojan.GenericKD.47495963
NANO-AntivirusVirus.Win32.Virut.pnbk
TencentVirus.Win32.Virut.tw
Ad-AwareTrojan.GenericKD.47495963
EmsisoftTrojan.GenericKD.47495963 (B)
ComodoVirus.Win32.Virut.D@1h82v0
BaiduWin32.Virus.Virut.i
VIPREVirus.Win32.Virut.b (v)
TrendMicroPE_VIRUT.GEN-2
McAfee-GW-EditionBehavesLike.Win32.Virut.nm
SophosML/PE-A + W32/Vetor-DAM
IkarusVirus.Win32.Virut
JiangminWin32/Virut.Gen
AviraW32/Virut.U
Antiy-AVLTrojan/Generic.ASVirus.14B
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataTrojan.GenericKD.47495963
CynetMalicious (score: 100)
MAXmalware (ai score=87)
TrendMicro-HouseCallPE_VIRUT.GEN-2
YandexWin32.Virut.Gen.5
SentinelOneStatic AI – Malicious PE
FortinetW32/Virut.fam
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Virut.O?

Win32/Virut.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment