Malware

VirTool:MSIL/Obfuscator.BH removal tips

Malware Removal

The VirTool:MSIL/Obfuscator.BH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:MSIL/Obfuscator.BH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:MSIL/Obfuscator.BH?


File Info:

crc32: C558AAED
md5: 5cb3c168eef6ddfe7cabe5a18ed2b647
name: 5CB3C168EEF6DDFE7CABE5A18ED2B647.mlw
sha1: a2c871ac40567e57e845d74144f85dace128b9f5
sha256: dce16831ef3bacce99b868331f1b8d11c88e7a796cb6868e23ccc4be6acef629
sha512: 7ecb0a9125b7adc81dbb3e80a18bd309286864bd216810d521b13a48fb1823fe516e5869d6104d96ae2d32d606dbd367ffd58c49421adc0fc39e389be89e7677
ssdeep: 1536:5AqGT+6XzxUFRbkpE9Ja6hIlEADlLTRG1baS3PB58dRgWbRW9mawF:5s9CzJz3J58gGh
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: x2.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: x2.exe

VirTool:MSIL/Obfuscator.BH also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSIL.8
ALYacGen:Variant.MSIL.8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.MSIL.8
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Comet.dkfyez
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Generic.Szlr
Ad-AwareGen:Variant.MSIL.8
EmsisoftGen:Variant.MSIL.8 (B)
ComodoMalware@#1nibasalxs5ii
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebBackDoor.Comet.94
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
FireEyeGeneric.mg.5cb3c168eef6ddfe
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.dogsz
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=82)
MicrosoftVirTool:MSIL/Obfuscator.BH
ArcabitTrojan.MSIL.8
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.MSIL.8
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.1Table.C526920
McAfeeArtemis!5CB3C168EEF6
ESET-NOD32a variant of MSIL/Injector.ASB
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_54%
FortinetMSIL/Injector.CLB!tr
BitDefenderThetaGen:NN.ZemsilF.34804.gm0@aCOs3E
AVGWin32:Malware-gen
Qihoo-360Generic/HEUR/Malware.QVM03.Gen

How to remove VirTool:MSIL/Obfuscator.BH?

VirTool:MSIL/Obfuscator.BH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment