Malware

Win32:VirLock-N [Trj] removal tips

Malware Removal

The Win32:VirLock-N [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VirLock-N [Trj] virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:VirLock-N [Trj]?


File Info:

name: A88E7DC5977EE1540019.mlw
path: /opt/CAPEv2/storage/binaries/fac0e30187e252fd27972daa5c2ad3d273bef9cd0be3626b8a53a136b7fac743
crc32: 23334D57
md5: a88e7dc5977ee1540019cd0e841516bc
sha1: ef74d752b39b9aef875d4d1f7bf8ae92e5ee9f95
sha256: fac0e30187e252fd27972daa5c2ad3d273bef9cd0be3626b8a53a136b7fac743
sha512: 321fa2befc28cb7f91032c0db45e8f098e693380703a12dafc09ba0f255077e36ef47151227295260472d31a403f7dfdecfabdca16919ed8c8d7db503e0d55cb
ssdeep: 6144:UtyyvcnhWWxJtXreOU2Tve2u+gdGLyPGTkUG:MEnhWWxJtrUmev+I/PGe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170244AD2F11A07BBFC5832646DD93684E60C806AE263CC3D139708E9B59D5ED6DC837A
sha3_384: 3d56cbc57bd2ab9f06090007e0f67403b05514fe2c871d805585e6577afd0e58a12f12699480cf55f3e9781ad3599ffb
ep_bytes: bfe2a10500b88bd4060081c70b500000
timestamp: 1970-01-01 00:02:03

Version Info:

0: [No Data]

Win32:VirLock-N [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Obfus.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Obfus.3.Gen
ClamAVBC.Win.Virus.Ransom-9157.A
FireEyeTrojan.Obfus.3.Gen
SkyhighBehavesLike.Win32.VirRansom.dc
Cylanceunsafe
ZillyaVirus.PolyRansom.Win32.1
SangforRansom.Win32.Save.a
K7AntiVirusVirus ( 0040f99f1 )
AlibabaRansom:Win32/Polyransom.A
K7GWVirus ( 0040f99f1 )
Cybereasonmalicious.2b39b9
VirITWin32.CryptorGen.B
SymantecTrojan.Gen.2
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.Obfus.3.Gen
AvastWin32:VirLock-N [Trj]
TACHYONVirus/W32.VirRansom.C
EmsisoftTrojan.Obfus.3.Gen (B)
DrWebWin32.VirLock.1
VIPRETrojan.Obfus.3.Gen
TrendMicroPE_VIRLOCK.F
SophosW32/VirRnsm-O
IkarusVirus-Ransom.FileLocker
GDataTrojan.Obfus.3.Gen
JiangminWin32/Polyransom.a
GoogleDetected
Antiy-AVLVirus/Win32.PolyRansom.a
XcitiumPacked.Win32.Graybird.B@5hgpd5
ArcabitTrojan.Obfus.3.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/S-27bc0672!Eldorado
AhnLab-V3Win32/Nabucur
Acronissuspicious
McAfeeW32/VirRansom
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallPE_VIRLOCK.F
RisingTrojan.Vindor!8.10CC (TFE:3:3SRJ7eZLjb)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.PolyRansom.a
FortinetW32/VirRansom.D9F1!tr
BitDefenderThetaAI:FileInfector.1F8DFD280F
AVGWin32:VirLock-N [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:VirLock-N [Trj]?

Win32:VirLock-N [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment