Virtool

Virtool.16508 removal tips

Malware Removal

The Virtool.16508 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virtool.16508 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Hebrew
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Virtool.16508?


File Info:

name: 4A6FFE547A65AA0D344C.mlw
path: /opt/CAPEv2/storage/binaries/d867392162440a865d5880c7df1671b5700e2f2d5e0166e1cde267ce7dcecfdd
crc32: BE73E89C
md5: 4a6ffe547a65aa0d344cfe2c3a6cc2d0
sha1: 19413b9ad6abb0fad700eb5c752961acb7e21f88
sha256: d867392162440a865d5880c7df1671b5700e2f2d5e0166e1cde267ce7dcecfdd
sha512: a24035a6d4aa73d5ee7df2b3d1d77061b21bb4ed11fa5babe42a02ea55866e174873a9e995c68c3ea7a6e7e232588088404b50f48d70fcdc22899f14bfb48868
ssdeep: 192:nQx8ZUawO8qU/LDZJpuuU8hsTJ6jPyztWz8lpZ2vlr8l+Sykth3et24Yvm1PHwlk:mLDTs8hsF6qtK8lzQ8+Sych3mYvCPHx5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1829D9AB320C9DAC18405366D13CABD77303D3A9D155E073ED4674F3E36756EC02A6A
sha3_384: 4982ab635990c89b724e6e99adf6cf1123972c246aa8a9083bf1e98b464bd968f28a1269d20dedac33cf726433c23e26
ep_bytes: 60e80000000083cdff31db5e8dbefa1f
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Virtool.16508 also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Generic.3!c
MicroWorld-eScanVirtool.16508
McAfeeArtemis!4A6FFE547A65
CylanceUnsafe
SangforTrojan.Script.Phonzy.A
Cybereasonmalicious.47a65a
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
BitDefenderVirtool.16508
NANO-AntivirusRiskware.Win32.CYQQ0530.dgioce
Ad-AwareVirtool.16508
SophosPatch Crack (PUA)
ComodoMalware@#2xbdutnne25lo
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.lc
FireEyeGeneric.mg.4a6ffe547a65aa0d
EmsisoftVirtool.16508 (B)
IkarusVirtool
GDataVirtool.16508
JiangminTrojan.Generic.dyzrt
Antiy-AVLTrojan/Generic.ASMalwS.588CBD
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacVirtool.16508
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GameCrack.B!tr
WebrootW32.Malware.Gen
PandaTrj/CI.A

How to remove Virtool.16508?

Virtool.16508 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment