Malware

What is “VirTool:Win32/CeeInject.AAG!bit”?

Malware Removal

The VirTool:Win32/CeeInject.AAG!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject.AAG!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Appends a known encryptJJS ransomware file extension to files that have been encrypted
  • Anomalous binary characteristics

How to determine VirTool:Win32/CeeInject.AAG!bit?


File Info:

crc32: F924B27D
md5: 64ef87a5272b691ce8c080be74286f07
name: 64EF87A5272B691CE8C080BE74286F07.mlw
sha1: 776b134d905f1aa17d8078b9bba86f171cb4ba97
sha256: 7e5e6e8e45faf59081c4c479c93e27b4685b60824ed83314002276852a3b9c8a
sha512: 0fc3b6918497c7a8223655ccdfbeedf23aac8be8b1a7d70f002c2916330dc2eb450736369045538945fb460d719c9ae8d0059a18855d9627d0d566909396f93d
ssdeep: 3072:z/mkJagiZBtxs+T4z7E8AOPm88pD92faXUfN+pcLEoRX0:DmgagiXsvKP88x9lUfWcLEoRX0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: tgabhryj.exe
FileVersion: 4.5.8
Translation: 0x0809 0x04b0

VirTool:Win32/CeeInject.AAG!bit also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
CynetMalicious (score: 100)
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.648
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/GandCrypt.3efb9796
K7GWTrojan ( 0053d5971 )
K7AntiVirusTrojan ( 0053d5971 )
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKQW
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan-Ransom.Win32.GandCrypt.esy
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.GandCrypt.fhpdwe
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentWin32.Trojan.Gandcrypt.Wqnn
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-S + Mal/GandCrab-B
ComodoTrojWare.Win32.TrojanSpy.Ursnif.EM@7vyz23
BitDefenderThetaGen:NN.ZexaF.34628.ku0@aSOh13aG
TrendMicroTrojanSpy.Win32.URSNIF.SMKB.hp
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
FireEyeGeneric.mg.64ef87a5272b691c
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1106537
eGambitUnsafe.AI_Score_99%
MicrosoftVirTool:Win32/CeeInject.AAG!bit
ArcabitTrojan.BRMon.Gen.4
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.N
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeePacked-FLX!64EF87A5272B
VBA32BScope.Backdoor.Androm
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMKB.hp
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GMSM!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.32b

How to remove VirTool:Win32/CeeInject.AAG!bit?

VirTool:Win32/CeeInject.AAG!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment