Malware

Exploit.CVE20167255 removal instruction

Malware Removal

The Exploit.CVE20167255 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.CVE20167255 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Exploit.CVE20167255?


File Info:

crc32: 504724E6
md5: 46336f5d40640c2b25a2238b32545243
name: 46336F5D40640C2B25A2238B32545243.mlw
sha1: 913d9cdd875de0137902b7d8c20f6a604d53c52c
sha256: 4e1ad61d1457e11a050cdd335ddc680002b2a5aa4381d9e325efe9ddb318ce97
sha512: 48af5c3faef4f16b1b66476b27c7378242e2c32c54ed90e28c1e4e04bd5821ab083f48a73af46bb1a713e95d75a38dc5e142bb979d6fefb32754f3ce2bbc12b6
ssdeep: 3072:5Rg1EqJt5oBc6P591+n5rWf/JDVtKv3v91bo2wNxs25G8sTmZ3VjhfcB29IOSyE:5RgHMrgEf/dTk3vfoEBXCthkaS3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, effnaxfuv
InternalName: toalatspring.exe
FileVersion: 5.1
ProductVersion: 5.1.111.0
Translation: 0x0789 0x04b1

Exploit.CVE20167255 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.46336f5d40640c2b
CAT-QuickHealTrojan.Cloxer.A06
ALYacTrojan.Ransom.GandCrab.Gen.2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Packed.Gandcrab-6520432-4
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 0056ea8e1 )
Cybereasonmalicious.d40640
CyrenW32/S-9659e02a!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Gandcrab-6535271-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Chapak.faykjx
ViRobotTrojan.Win32.GandCrab.Gen.A
AegisLabHacktool.Win32.CVE-2016-7255.3!c
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
ComodoTrojWare.Win32.Magniber.GH@7mr2pk
F-SecureHeuristic.HEUR/AGEN.1102756
DrWebTrojan.MulDrop8.17708
ZillyaExploit.CVE.Win32.2126
TrendMicroRansom_GANDCRAB.SMALY-5
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
MaxSecureRansomeware.CRAB.gen
SophosML/PE-A + Mal/Agent-AUL
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Fareit.snh
AviraHEUR/AGEN.1102756
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.Ransom.GandCrab.Gen.2
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
McAfeeGenericRXFG-AZ!46336F5D4064
TACHYONRansom/W32.GandCrab
VBA32BScope.Exploit.CVE-2016-7255
MalwarebytesExploit.CVE20167255
PandaTrj/Genetic.gen
ESET-NOD32Win32/Filecoder.GandCrab.B
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-5
TencentMalware.Win32.Gencirc.10b150b4
YandexTrojan.PWS.Coins!P004/XsNcgk
IkarusTrojan.Kryptik
FortinetW32/GenKryptik.DQHN!tr
BitDefenderThetaGen:NN.ZexaF.34590.ou1@amfTd1oi
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.ec9

How to remove Exploit.CVE20167255?

Exploit.CVE20167255 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment