Malware

VirTool:Win32/Binder information

Malware Removal

The VirTool:Win32/Binder is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Binder virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/Binder?


File Info:

crc32: F31FE23A
md5: 961ddf3c469283ff302968d7bc594bf8
name: 961DDF3C469283FF302968D7BC594BF8.mlw
sha1: 613ba0dfa2251545f8201badabbe015fcc7adeed
sha256: 0857dd8bda1d82615f39626aad6f70b697c9a2ba77c01e0057386765153bb678
sha512: 30170eaaff4f196035da7886446ea3eb1df50f58951167962f188eaf9a9cdc557c187ec6886c9091d116826ff44cc06456834d4edcd11fc7dff4bbfe8b4e75fb
ssdeep: 3072:XwCHql0p4gSCAJFPZNUZgQaAcuBFE6uvf:gQnp32JFsR2m2f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/Binder also known as:

K7AntiVirusRiskware ( 0015e4f11 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen.20160
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.1100
CylanceUnsafe
ZillyaTrojan.PornoBlocker.Win32.12840
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/PornoBlocker.baedfa23
K7GWRiskware ( 0015e4f11 )
Cybereasonmalicious.c46928
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.Agent.WA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Buzus-8907
KasperskyTrojan-Ransom.Win32.PornoBlocker.ekyi
BitDefenderGen:Variant.Barys.1100
NANO-AntivirusTrojan.Win32.Buzus.wfzhp
SUPERAntiSpywareTrojan.Agent/Gen-Buzus
MicroWorld-eScanGen:Variant.Barys.1100
TencentMalware.Win32.Gencirc.10baeca7
Ad-AwareGen:Variant.Barys.1100
SophosMal/EncPk-YY
ComodoTrojWare.Win32.Spy.Zbot.DTNY@4pp6dp
BitDefenderThetaGen:NN.ZexaF.34688.lqZ@amkzqXlc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.ch
FireEyeGeneric.mg.961ddf3c469283ff
EmsisoftGen:Variant.Barys.1100 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Buzus.awjp
WebrootW32.Malware.Gen
AviraTR/ATRAPS.Gen5
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Buzus.(kcloud)
MicrosoftVirTool:Win32/Binder
AegisLabTrojan.Win32.Buzus.lwc3
GDataGen:Variant.Barys.1100
TACHYONTrojan/W32.Buzus.183535
AhnLab-V3Trojan/Win32.Buzus.C6
McAfeePWS-Zbot-FBEM!961DDF3C4692
MAXmalware (ai score=100)
VBA32BScope.Trojan-Dropper.Susa
PandaTrj/Genetic.gen
RisingRansom.PornoBlocker!8.24E (CLOUD)
YandexTrojan.Injector!UgnQ/x22HDU
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.2368126.susgen
FortinetW32/Buzus.HWP!tr
AVGWin32:Trojan-gen

How to remove VirTool:Win32/Binder?

VirTool:Win32/Binder removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment