Malware

Should I remove “VirTool.Vbinder.CO5”?

Malware Removal

The VirTool.Vbinder.CO5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What VirTool.Vbinder.CO5 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine VirTool.Vbinder.CO5?


File Info:

crc32: 9D3B33D5
md5: a1696a197db00dda0313df907374dee1
name: 260997.jpg
sha1: c3c61f065ee81bf3e3fb024372cfe8d341c99714
sha256: 78db3d9f1d11e47fd9d853e5f9296130caeb5348d234b7d150d58e521ba66488
sha512: 140d3b63f84a6d43f8af0ad50b75fe309ddcf51a3e2c701f6784abc2a5068b3534531521c72f0f4daf20870ee9afdb4b52eb34062aa313ea7b464fa9f8beb914
ssdeep: 24576:i+Wn8RZz/gMbER17gGqMpvDHeHi7YmJXFsoPvWZ:iORZDgqER17gjMpDeHE5Fso3W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool.Vbinder.CO5 also known as:

BkavW32.GenericBinderLnr.Trojan
MicroWorld-eScanGen:Variant.Binder.1
CMCHackTool.Win32.Binder!O
CAT-QuickHealVirTool.Vbinder.CO5
McAfeeTrojan-FDDZ!A1696A197DB0
MalwarebytesHackTool.Binder
SUPERAntiSpywareTrojan.Agent/Gen-Binder
K7AntiVirusTrojan ( 004babd11 )
AlibabaHackTool:Win32/Binder.5d1d251f
K7GWTrojan ( 004babd11 )
Cybereasonmalicious.97db00
ArcabitTrojan.Binder.1
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.32250.svW@aO0fn7mG
CyrenW32/Backdoor.FVDJ-1096
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.AGBZ
BaiduWin32.Trojan-Dropper.Binder.m
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.Binder-6
KasperskyHackTool.Win32.Binder.bs
BitDefenderGen:Variant.Binder.1
Paloaltogeneric.ml
AegisLabHacktool.Win32.Binder.lo77
Ad-AwareGen:Variant.Binder.1
EmsisoftGen:Variant.Binder.1 (B)
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
F-SecureTrojan.TR/Injector.ijmoi
DrWebTrojan.MulDrop2.39589
VIPRETrojan-Dropper.Win32.Binder.bs (v)
TrendMicroTROJ_BINDER_FC1700C9.UVPA
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a1696a197db00dda
SophosMal/Fareit-V
SentinelOneDFI – Malicious PE
F-ProtW32/Backdoor2.HKXU
JiangminHackTool.Binder.bh
AviraTR/Injector.ijmoi
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftVirTool:Win32/Vbinder.CO
Endgamemalicious (high confidence)
ViRobotTrojan.Win32.A.Swisyn.49120
ZoneAlarmHackTool.Win32.Binder.bs
GDataWin32.Trojan.Binder.A
AhnLab-V3HackTool/Win32.Vbinder.R12127
Acronissuspicious
VBA32Binder.Celesty
ALYacGen:Variant.Binder.1
CylanceUnsafe
ESET-NOD32Win32/TrojanDropper.Binder.NBH
TrendMicro-HouseCallTROJ_BINDER_FC1700C9.UVPA
RisingDropper.Binder!1.AEB1 (CLASSIC)
YandexHackTool.Binder!IMtdREcP3/k
IkarusTrojan.Win32.Dorv
MaxSecureHackTool.W32.Binder.bs
FortinetW32/Dropper.NBH!tr
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Hacktool.4af

How to remove VirTool.Vbinder.CO5?

VirTool.Vbinder.CO5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment