Malware

About “VirTool:Win32/CeeInject.A” infection

Malware Removal

The VirTool:Win32/CeeInject.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

Related domains:

private.beer-rox.net

How to determine VirTool:Win32/CeeInject.A?


File Info:

crc32: 4A518C8E
md5: 43bf6bd51791dd47d7c8797e8dbce521
name: 43BF6BD51791DD47D7C8797E8DBCE521.mlw
sha1: 2c9477864627ba73f5923c3f344b53d6348b5aec
sha256: 1869853a07cf31e43569cc9142f7934a5c81ff6dfe21902aa0693bc905824fb4
sha512: 271ad2fe1a07b21b4f69e49a2618365120972837d4e0fd15bfd81fd4154cc8a4e2a2e2728657cb3c6c045991dee057c148a9edb47c023f4585de27e927569425
ssdeep: 1536:+7KnHMN8zvdofYRxYv0sYnpMU4HB+9AL30QOLXix5Ch4Z60XKnslzd:+bN8DdofYRxYv0sSpMU4HB+9AL30QqX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TeamViewer GmbH
InternalName: TeamViewer
FileVersion: 4.1.6043.0
CompanyName: TeamViewer GmbH
PrivateBuild: TeamViewer Remote Control Application
LegalTrademarks: TeamViewer
ProductName: TeamViewer
ProductVersion: 4.1
FileDescription: TeamViewer Remote Control Application
OriginalFilename: TeamViewer.exe
Translation: 0x0409 0x04b0

VirTool:Win32/CeeInject.A also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.EmotetU.Gen.eq0@biDBK7
FireEyeGeneric.mg.43bf6bd51791dd47
CAT-QuickHealW32.Virut.G
McAfeeBackdoor-DWV
MalwarebytesMalware.AI.222285832
VIPRETrojan.Win32.Generic!BT
K7AntiVirusHacktool ( 005288d11 )
BitDefenderTrojan.EmotetU.Gen.eq0@biDBK7
K7GWHacktool ( 005288d11 )
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderThetaAI:Packer.3E41B9201E
CyrenW32/CeeInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/ASuspect.HHABZ
APEXMalicious
AvastWin32:Vitro [Inf]
ClamAVWin.Trojan.Dropper-2660
KasperskyPacked.Win32.Krap.bh
NANO-AntivirusTrojan.Win32.Droco.zjdu
ViRobotDropper.Droco.218608
RisingTrojan.Generic@ML.100 (RDML:+1AG4IYQniKqbEBDNFIeIQ)
Ad-AwareTrojan.EmotetU.Gen.eq0@biDBK7
SophosML/PE-A + Mal/EncPk-JU
ComodoTrojWare.Win32.TrojanDropper.Droco.A@1corx3
F-SecureTrojan-Dropper:W32/Malis.gen!D
DrWebBackDoor.IRC.Sdbot.18753
ZillyaTrojan.Injector.Win32.375174
TrendMicroBKDR_BIFROSE.SME
McAfee-GW-EditionBehavesLike.Win32.Emotet.lc
EmsisoftTrojan.EmotetU.Gen.eq0@biDBK7 (B)
IkarusDownloader.IRCBot
JiangminTrojanDropper.Droco.a
WebrootVir.Tool.Gen
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Packed]/Win32.Krap
MicrosoftVirTool:Win32/CeeInject.A
ArcabitTrojan.EmotetU.Gen.E5EAAB
ZoneAlarmPacked.Win32.Krap.bh
GDataTrojan.EmotetU.Gen.eq0@biDBK7
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Poison.C66657
Acronissuspicious
VBA32OScope.Buzus.ah
ALYacTrojan.EmotetU.Gen.eq0@biDBK7
CylanceUnsafe
PandaTrj/Dropper.WF
ESET-NOD32Win32/Injector.QF
TrendMicro-HouseCallBKDR_BIFROSE.SME
YandexTrojan.GenAsa!y/wCSUbsx2k
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.IA!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.51791d
Qihoo-360Malware.Radar01.Gen

How to remove VirTool:Win32/CeeInject.A?

VirTool:Win32/CeeInject.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment