Malware

What is “Win64/Bolik.T”?

Malware Removal

The Win64/Bolik.T is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Bolik.T virus can do?

  • Anomalous binary characteristics

How to determine Win64/Bolik.T?


File Info:

crc32: 74752AAE
md5: 2a5f82ea78e765ea06e241edc8439af4
name: 2A5F82EA78E765EA06E241EDC8439AF4.mlw
sha1: b66dddb1a485b8e1a4fc8ee087788f5235508deb
sha256: 1cb403bdcf4f981f79868c93b7dd470500b07cee9ff0e1ee269822e6bfeac9b0
sha512: b4312fe55a3c3ddc884ef5a15b0f426827b7417eae4d9208df7851178e565372135b4a048674f517c5f225290348ec7d344a1398bcd72f565b30fd9d32b5ccd5
ssdeep: 12288:ARH+S+hQcDGF9yXdMIHnKwZ7D4vWwUjlyZK2BIp+RPE0LodGY3wif2LZ4QNUi:ARH+nQbTyPHKw7svSoZTBIQRPHwG7pR
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: BAAUPDATE
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
OleSelfRegister:
ProductVersion: 6.1.7600.16385
FileDescription: BitLocker Access Agent Update Utility
OriginalFilename: BAAUPDATE.EXE
Translation: 0x0409 0x04b0

Win64/Bolik.T also known as:

K7AntiVirusVirus ( 005092211 )
LionicVirus.Win64.Tpun.n!c
Elasticmalicious (high confidence)
DrWebWin32.Bolik.1
CAT-QuickHealW64.Tpun.A7
ALYacWin64.Bolik.Gen
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWVirus ( 005092211 )
Cybereasonmalicious.a78e76
SymantecW64.Bolik.A!inf
ESET-NOD32a variant of Win64/Bolik.T
APEXMalicious
AvastWin64:Malware-gen
KasperskyVirus.Win64.Tpun.a
BitDefenderWin64.Bolik.Gen
NANO-AntivirusVirus.Win64.Tpun.ejvowt
MicroWorld-eScanWin64.Bolik.Gen
TencentWin64.Virus.Tpun.Hrpn
Ad-AwareWin64.Bolik.Gen
SophosMal/Generic-S
McAfee-GW-EditionW64/Bolik!2A5F82EA78E7
FireEyeGeneric.mg.2a5f82ea78e765ea
EmsisoftWin64.Bolik.Gen (B)
AviraTR/Patched.Bolik.Gen8
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin64.Bolik.Gen
McAfeeW64/Bolik!2A5F82EA78E7
MAXmalware (ai score=100)
PandaGeneric Suspicious
IkarusTrojan.Win64.Patched
FortinetW64/Tpun.A
AVGWin64:Malware-gen
Paloaltogeneric.ml

How to remove Win64/Bolik.T?

Win64/Bolik.T removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment