Malware

VirTool:Win32/CeeInject.AAW!bit (file analysis)

Malware Removal

The VirTool:Win32/CeeInject.AAW!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject.AAW!bit virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

s3.amazonaws.com
ocsp.digicert.com
crl4.digicert.com
crl3.digicert.com
fakbrasil.com.br

How to determine VirTool:Win32/CeeInject.AAW!bit?


File Info:

crc32: 05EA834B
md5: 264bf883e74b69ff1f7f0176fef51e74
name: 264BF883E74B69FF1F7F0176FEF51E74.mlw
sha1: 3dddb37d93f62afd2a1ff5617fa2f606dbdd9b56
sha256: 8f40cf972815296af67d0e00f16f759cbd7926ed120f1c4be592332138960586
sha512: 01813c92b4816d49cb4f8d731575dfee13d3510a32f140a36e5587840bcf14e13796bdac5dd58ccba84a24138b5d638c587c7418ac6fb788d0ec0680e0b5971e
ssdeep: 1536:ZPFkMLB9uRx2Ur4H444h4Yvh5iTkGzcSYiy+u6OUu3yUyJCbItwc3F7/d:RFk8/U4H444hhiwGzcGy+u0Sc3pd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/CeeInject.AAW!bit also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Trojan.Downloader.D8Y@a4TB@oci
FireEyeGeneric.mg.264bf883e74b69ff
McAfeeGenericRXDX-TJ!264BF883E74B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Trojan.Downloader.D8Y@a4TB@oci
K7GWTrojan-Downloader ( 0052538d1 )
K7AntiVirusTrojan-Downloader ( 0052538d1 )
BitDefenderThetaGen:NN.ZexaF.34804.D8Y@a4TB@oci
SymantecDownloader
AvastWin32:Malware-gen
AlibabaVirTool:Win32/CeeInject.9a925994
NANO-AntivirusTrojan.Win32.Dwn.exlsoy
TencentMalware.Win32.Gencirc.114cd901
Ad-AwareGen:Trojan.Downloader.D8Y@a4TB@oci
EmsisoftGen:Trojan.Downloader.D8Y@a4TB@oci (B)
ComodoMalware@#1yv9rpyx4448m
F-SecureHeuristic.HEUR/AGEN.1121995
ZillyaDownloader.Agent.Win32.348669
TrendMicroTROJ_GEN.R002C0CLD20
McAfee-GW-EditionBehavesLike.Win32.Generic.gz
SophosMal/Generic-S
IkarusTrojan.Win32.Tiny
JiangminTrojanDownloader.Banload.bnvd
AviraHEUR/AGEN.1121995
MAXmalware (ai score=84)
MicrosoftVirTool:Win32/CeeInject.AAW!bit
ArcabitTrojan.Downloader.E06AAA
GDataGen:Trojan.Downloader.D8Y@a4TB@oci
CynetMalicious (score: 85)
VBA32BScope.TrojanDownloader.Banload
ALYacGen:Trojan.Downloader.D8Y@a4TB@oci
MalwarebytesMalware.AI.3649650434
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.DUV
TrendMicro-HouseCallTROJ_GEN.R002C0CLD20
RisingDownloader.Agent!8.B23 (CLOUD)
YandexTrojan.GenAsa!xfI98SaSI0w
FortinetW32/Agent.DUV!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Downloader.83e

How to remove VirTool:Win32/CeeInject.AAW!bit?

VirTool:Win32/CeeInject.AAW!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment