Malware

Should I remove “VirTool:Win32/CeeInject.AOB!bit”?

Malware Removal

The VirTool:Win32/CeeInject.AOB!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject.AOB!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Czech
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com
update.googleapis.com

How to determine VirTool:Win32/CeeInject.AOB!bit?


File Info:

crc32: 15CDDC52
md5: 7b22baf426c19830a86553ecdb2c938e
name: 7B22BAF426C19830A86553ECDB2C938E.mlw
sha1: 748833ff90f5fce664287d95bab59e0f8ed5068b
sha256: 663bcec87e768cd5d1e7be1808e38e2d79617ba137a8c272de6652528d4fcf02
sha512: fa55791144cc0c5df6d118a5a1fb2629ad4bbd6791fa88e50d53d71c38ca63a6072888c99465b7870ed8e0d4ae8e438daec03307db1433db8439b9a4610a7187
ssdeep: 3072:TvePWNPQ3jgSn6PEFrX+IFt/YLnDmoo8BpOYkYqkM6ZerEPIISdcTF7YH8:TvHJcFrX+oRYTioo8WYkYlfNIzcl
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

VirTool:Win32/CeeInject.AOB!bit also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005483901 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.41560
CynetMalicious (score: 100)
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
SangforHacktool.Win32.CeeInject.AOB!bit
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Genasom.ali1000102
K7GWTrojan ( 005483901 )
Cybereasonmalicious.426c19
CyrenW32/S-facc7782!Eldorado
SymantecRansom.GandCrab
ESET-NOD32a variant of Win32/Kryptik.GPYF
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Gandcrab-6914446-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.54044
NANO-AntivirusTrojan.Win32.Kryptik.fnhmmu
ViRobotTrojan.Win32.GandCrab.Gen.B
MicroWorld-eScanTrojan.GenericKDZ.54044
TencentWin32.Trojan.Generic.Ahok
Ad-AwareTrojan.GenericKDZ.54044
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.Propagate.MO@8259at
BitDefenderThetaGen:NN.ZexaF.34058.jmGfaKRnZEhO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.RansomGandCrab.cc
FireEyeGeneric.mg.7b22baf426c19830
EmsisoftTrojan.GenericKDZ.54044 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Propagate.yu
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_81%
Antiy-AVLTrojan/Generic.ASMalwS.2AA7A1F
MicrosoftVirTool:Win32/CeeInject.AOB!bit
ArcabitTrojan.Generic.DD31C
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKDZ.54044
TACHYONRansom/W32.GandCrab.319488
AhnLab-V3Trojan/Win32.Gandcrab.C3032433
Acronissuspicious
McAfeeArtemis!7B22BAF426C1
MAXmalware (ai score=80)
VBA32BScope.Trojan.Azden
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B5FD (CLASSIC)
YandexTrojan.GenAsa!wUQnq6pFhRQ
IkarusTrojan-PSW.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GPYC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.CeeInject.HwsBEpsA

How to remove VirTool:Win32/CeeInject.AOB!bit?

VirTool:Win32/CeeInject.AOB!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment