Worm

What is “Worm:Win32/Virenkqut.A”?

Malware Removal

The Worm:Win32/Virenkqut.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Virenkqut.A virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Unusual version info supplied for binary

How to determine Worm:Win32/Virenkqut.A?


File Info:

crc32: AA5EEDD4
md5: c074a8d9bdcf325868452af7ba8aeeba
name: C074A8D9BDCF325868452AF7BA8AEEBA.mlw
sha1: bad25e927d447414c47cca8072f01e3ef2a76f4a
sha256: 313e8722ba55c7f93632c7babeff9ac129e0b85422418a618d6f1bbf2421768e
sha512: 1db3f5178f094351c9e8ef7ed81b8ef6ab105287651e1c6d61e793a386ac3efaf5422e1a870bc248f61e23ef48c264b213ec71768f4ca666f4f093fcd4cf7206
ssdeep: 768:FfoU8EHyFRnDVEVagvP6JXmDlcVP34PIHfOdojpahYUPfGPDb:5yvVEVagvP6J2DlcVQoUojp5P
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Microsoftxae Windowsxae Operating System
InternalName: %ntfs%
FileVersion: 1.00
CompanyName: 0 KB
LegalTrademarks: Microsoftxae Windowsxae Operating System
Comments: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 1.00
FileDescription: System file
OriginalFilename: %ntfs%.exe

Worm:Win32/Virenkqut.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0055e3db1 )
LionicTrojan.Win32.Cosmu.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen3.17848
CynetMalicious (score: 100)
CAT-QuickHealTrojan.VBCrypt.MF.4942
ALYacGen:Trojan.Heur.cmLfrXbQh2fiy
CylanceUnsafe
ZillyaTrojan.Cosmu.Win32.10553
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.9bdcf3
CyrenW32/VBTrojan.17E!Maximus
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.VB.ANM
APEXMalicious
AvastWin32:Patched-AFR [Trj]
ClamAVWin.Dropper.Ramnit-9886751-0
KasperskyTrojan.Win32.Cosmu.atav
BitDefenderGen:Trojan.Heur.cmLfrXbQh2fiy
NANO-AntivirusTrojan.Win32.Cosmu.fagcgb
ViRobotTrojan.Win32.A.Cosmu.14848[UPX]
MicroWorld-eScanGen:Trojan.Heur.cmLfrXbQh2fiy
TencentMalware.Win32.Gencirc.10b3a9d1
Ad-AwareGen:Trojan.Heur.cmLfrXbQh2fiy
SophosMal/Generic-R + Mal/VB-F
ComodoMalware@#psnjpmbjya2e
BitDefenderThetaAI:Packer.103EB4B91D
VIPRETrojan.Win32.Generic!BT
TrendMicroPAK_Otorun8
McAfee-GW-EditionBehavesLike.Win32.Virus.pc
FireEyeGeneric.mg.c074a8d9bdcf3258
EmsisoftGen:Trojan.Heur.cmLfrXbQh2fiy (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Virut.bv
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.F7012E
MicrosoftWorm:Win32/Virenkqut.A
ArcabitTrojan.Heur.cmLfrXbQh2fiy
GDataGen:Trojan.Heur.cmLfrXbQh2fiy
AhnLab-V3Trojan/Win32.Cosmu.R90223
Acronissuspicious
McAfeeArtemis!C074A8D9BDCF
MAXmalware (ai score=100)
VBA32TScope.Trojan.VB
MalwarebytesPolyRansom.Virus.FileInfector.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallPAK_Otorun8
YandexTrojan.GenAsa!SVp0CD6+ugQ
IkarusTrojan-Banker.Win32.Bancos
MaxSecureTrojan.Malware.3534859.susgen
FortinetW32/AutoRun.ANM!tr
AVGWin32:Patched-AFR [Trj]

How to remove Worm:Win32/Virenkqut.A?

Worm:Win32/Virenkqut.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment