Malware

About “VirTool:Win32/CeeInject.BDQ!bit” infection

Malware Removal

The VirTool:Win32/CeeInject.BDQ!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject.BDQ!bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a file
  • Anomalous binary characteristics

How to determine VirTool:Win32/CeeInject.BDQ!bit?


File Info:

crc32: A70DB810
md5: c2b7c48bc3efe4efb3c3cc3a898fef0b
name: C2B7C48BC3EFE4EFB3C3CC3A898FEF0B.mlw
sha1: db20f2a3caa13e22f7a1cfdb50c93776a3020ca8
sha256: 0988d21e5049b9e4f69e3419a7632680b2277eccdb68b95d7a7d63baf2ab7043
sha512: 7be3f343e396cbfb4130b4a08638c3b119a568ca74eb4256834a4ed122134b1414260be61424f52cffc0ff045884f3e8076284714d9539c9535c3fc40850262c
ssdeep: 24576:lYIazKObATO2ZGBouC4m3DlZSJK4PceDACwo:liKO8qVouC7MK4Px+o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/CeeInject.BDQ!bit also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.62751
FireEyeGeneric.mg.c2b7c48bc3efe4ef
ALYacGen:Variant.Barys.62751
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Barys.62751
Cybereasonmalicious.bc3efe
TrendMicroTrojanSpy.Win32.LOKI.SMAD2.hp
SymantecTrojan.Gen.2
APEXMalicious
ClamAVWin.Malware.Smad-6922068-0
Ad-AwareGen:Variant.Barys.62751
SophosTroj/Agent-AJFK
F-SecureHeuristic.HEUR/AGEN.1126516
DrWebTrojan.PWS.Stealer.25962
InvinceaML/PE-A + Troj/Agent-AJFK
McAfee-GW-EditionBehavesLike.Win32.Fareit.bc
EmsisoftGen:Variant.Barys.62751 (B)
IkarusTrojan.Inject
JiangminTrojan.Kryptik.yp
AviraHEUR/AGEN.1126516
eGambitUnsafe.AI_Score_99%
MicrosoftVirTool:Win32/CeeInject.BDQ!bit
ArcabitTrojan.Barys.DF51F
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataGen:Variant.Barys.62751
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R261779
McAfeeGenericRXHR-PB!C2B7C48BC3EF
MAXmalware (ai score=87)
MalwarebytesTrojan.Injector
ESET-NOD32a variant of Win32/GenKryptik.DEDB
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD2.hp
RisingTrojan.Ymacco!8.11BE1 (TFE:2:bSRtW4lIhOQ)
YandexTrojan.GenAsa!fvXjRmSSYT4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/LOKI.2E00!tr
BitDefenderThetaGen:NN.ZelphiF.34590.WGW@a49tw8ci
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360HEUR/QVM20.1.352F.Malware.Gen

How to remove VirTool:Win32/CeeInject.BDQ!bit?

VirTool:Win32/CeeInject.BDQ!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment