Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

Worm.Win32.Viking.lw removal tips

Published May 1, 2024 Worm category 3 min read
Report context

What to verify before removal

Use this report for a controlled check of Worm.Win32.Viking.lw removal tips when the affected machine shows suspicious processes, dropped files, or payload delivery behavior. The goal is to verify the exact file and persistence path before quarantine.

Start by comparing the local file name with AFD8FA9CAD638531643E.mlw, then review the behavior notes for persistence entries, dropped files, unusual processes, and browser or network changes. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
AFD8FA9CAD638531643E.mlw
  • Compare the suspicious file name with AFD8FA9CAD638531643E.mlw.
  • Confirm the detection name matches Worm.Win32.Viking.lw removal tips before removing related files.
  • Review the report for persistence entries, dropped files, unusual processes, and browser or network changes so the cleanup is based on observed behavior, not only the label.
  • Run a full scan, quarantine confirmed detections, and restart before signing back in to sensitive accounts.

The Worm.Win32.Viking.lw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Worm.Win32.Viking.lw virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk
  • The sample wrote data to the system hosts file.
  • Uses suspicious command line tools or Windows utilities

How to determine Worm.Win32.Viking.lw?


File Info:

name: AFD8FA9CAD638531643E.mlw
path: /opt/CAPEv2/storage/binaries/3cef288eddfb9b0c125d0a3d94cf68d671e5b51f6c2e83ed829241d8774b729c
crc32: 08B0F543
md5: afd8fa9cad638531643e4e2623362fab
sha1: 66af67d59d45c026fcb6c9e4c90c5acfddb6bb86
sha256: 3cef288eddfb9b0c125d0a3d94cf68d671e5b51f6c2e83ed829241d8774b729c
sha512: 909b50977e489049629f9cdf05979d9bb9ccdaa5b9322b970432a91c38352c53b208d6696a10ab96f7c2ee27b2603feef4225ab22bce230780a3813fa5be7b37
ssdeep: 1536:27qnkAQtSaoGo5n4iLG0/WM6T3EKHSaYqemmjxh4sEVk2+I8K/XCKCGSqzV:nCSjGoLpWM6bblmjxhpck2+ufC58
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198E34A15B29CB3F6D0E281B8CE4DF2DAFD397D212B11448FBBA95B0D5E632C1592C252
sha3_384: fb7a168119ddeac17f74498c187b925c01099e306ac7df8939004e2fe99fa6120001b15243f4ea5cc069e14b9da657e5
ep_bytes: 90558bec83c4f0b89c0b4100eb950000
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm.Win32.Viking.lw also known as:

Bkav W32.LogOneG.Worm
Lionic Trojan.Win32.Turkojan.lixn
tehtris Generic.Malware
MicroWorld-eScan Win32.Worm.Viking.IZ
FireEye Generic.mg.afd8fa9cad638531
CAT-QuickHeal W32.Viking.gen
Skyhigh BehavesLike.Win32.Wabot.ch
McAfee Artemis!AFD8FA9CAD63
Cylance unsafe
Zillya Worm.Viking.Win32.43
Sangfor Trojan.Win32.Save.a
Alibaba Worm:Win32/Viking.ac42
BitDefenderTheta AI:Packer.07510BAB1D
VirIT Worm.Win32.Delf.BWR
Symantec W32.Looked.BK
ESET-NOD32 Win32/Viking.LU
APEX Malicious
Avast Win32:Delf-BTL [Trj]
ClamAV Win.Trojan.Philis-85
Kaspersky Worm.Win32.Viking.lw
BitDefender Win32.Worm.Viking.IZ
Tencent Virus.Win32.Viking.h
Emsisoft Win32.Worm.Viking.IZ (B)
Baidu Win32.Worm.Viking.a
F-Secure Trojan.TR/Hijacker.Gen
DrWeb Win32.HLLW.Gavir.72
VIPRE Win32.Worm.Viking.IZ
TrendMicro PE_LOOKED.ACX
Trapmine malicious.high.ml.score
Sophos W32/Looked-EB
Paloalto generic.ml
Jiangmin Worm/Viking.qr
ALYac Win32.Worm.Viking.IZ
Varist W32/DelfInject.A.gen!Eldorado
Avira TR/Hijacker.Gen
MAX malware (ai score=88)
Antiy-AVL Worm/Win32.Viking.jo
Kingsoft Worm.Viking.hw.940032
Microsoft Virus:Win32/Viking.KX
Xcitium Virus.Win32.Viking.~A@2v6vn
Arcabit Win32.Worm.Viking.IZ
ViRobot Worm.Win32.Viking.Gen
ZoneAlarm Worm.Win32.Viking.lw
GData Win32.Trojan.PSE1.16GEQY6
Cynet Malicious (score: 100)
AhnLab-V3 Win32/Viking.Gen
Acronis suspicious
VBA32 BScope.Trojan.Click
Google Detected
Malwarebytes Generic.Malware.AI.DDS
Panda W32/Viking.VH
TrendMicro-HouseCall PE_LOOKED.ACX
Rising Worm.Win32.Viking.ib (CLASSIC)
Yandex Trojan.GenAsa!lvpR4wpt6bc
Ikarus Worm.Win32.Looked.E.dam#2
Fortinet W32/Viking.LU
AVG Win32:Delf-BTL [Trj]
DeepInstinct MALICIOUS
alibabacloud Worm:Win/Viking.LC

How to remove Worm.Win32.Viking.lw?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.