Malware

VirTool:Win32/CeeInject.MH!bit removal

Malware Removal

The VirTool:Win32/CeeInject.MH!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject.MH!bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

proudsoldier1000.hopto.org

How to determine VirTool:Win32/CeeInject.MH!bit?


File Info:

crc32: 3C686DD7
md5: 2c3a7afd7456ad9f7878f48d9666891a
name: 2C3A7AFD7456AD9F7878F48D9666891A.mlw
sha1: 578cf00ce93708f6ba148af73ddaf37cb36053a2
sha256: cf778504a69a421124e8a92f20c5afd8ba4d770c0300b27eafb396df48ccc3f9
sha512: a1e5cb3b19e34b0c83176d7f4d9b30c5c18bf9cd2743d2e163bc352ba968e3677f1b3fac77f39cf1ff9737f7d1fecc557b48eebe79f07c875541a543b4085e2e
ssdeep: 12288:Yik3QNO/NnGS3JrlXQ7ntULkCNt8RMMVLA7AR5NYQMMMMMMMMMMMMMMMMMMUMMM:QQNaQYrlgbtzCNte56QMMMMMMMMMMMM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1993-2015 Yukihiro Matsumoto
InternalName: ruby.exe
FileVersion: 2.3.0p0
CompanyName: http://www.ruby-lang.org/
Comments: 2015-12-25
ProductName: Ruby interpreter 2.3.0p0 [i386-mingw32]
ProductVersion: 2.3.0p0
FileDescription: Ruby interpreter (CUI) 2.3.0p0 [i386-mingw32]
OriginalFilename: ruby.exe
Translation: 0x0000 0x04b0

VirTool:Win32/CeeInject.MH!bit also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.20402
FireEyeGeneric.mg.2c3a7afd7456ad9f
CAT-QuickHealTrojan.Netwire
ALYacGen:Variant.Ursu.20402
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.NetWire.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050c97c1 )
BitDefenderGen:Variant.Ursu.20402
K7GWTrojan ( 0050c97c1 )
Cybereasonmalicious.d7456a
BitDefenderThetaAI:Packer.43E6ADB716
CyrenW32/Injector.JD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DOIF
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Fareit-6985088-0
KasperskyTrojan.Win32.NetWire.fvh
AlibabaTrojan:Win32/DelfInject.ali2000015
TencentWin32.Trojan.Generic.Hrpi
Ad-AwareGen:Variant.Ursu.20402
EmsisoftGen:Variant.Ursu.20402 (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
F-SecureHeuristic.HEUR/AGEN.1105364
DrWebBackDoor.Wirenet.328
TrendMicroTROJ_GEN.R002C0DAG21
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosMal/Generic-R + Mal/Fareit-M
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ebnmd
AviraHEUR/AGEN.1105364
MicrosoftVirTool:Win32/CeeInject.MH!bit
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Ursu.D4FB2
AhnLab-V3Trojan/Win32.Inject.R197901
ZoneAlarmTrojan.Win32.NetWire.fvh
GDataGen:Variant.Ursu.20402
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!2C3A7AFD7456
MAXmalware (ai score=85)
VBA32BScope.TrojanPSW.Tepfer
MalwarebytesMalware.AI.1760542898
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DAG21
RisingTrojan.Generic!8.C3 (C64:YzY0Opront/zy+N9)
YandexTrojan.GenAsa!uJc2e8FQQo8
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DOJP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove VirTool:Win32/CeeInject.MH!bit?

VirTool:Win32/CeeInject.MH!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment