Malware

VirTool:Win32/CeeInject!CR (file analysis)

Malware Removal

The VirTool:Win32/CeeInject!CR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject!CR virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk

How to determine VirTool:Win32/CeeInject!CR?


File Info:

name: 8B939E86E1C36182A77A.mlw
path: /opt/CAPEv2/storage/binaries/8ce218856819dcddb1cb197409607d40765d073434d9ca6662107f6e9abef509
crc32: 08103091
md5: 8b939e86e1c36182a77a6b97aad7f2e9
sha1: 5cb815c5383e65102ff6f73f50bdfbfcdcee6ebe
sha256: 8ce218856819dcddb1cb197409607d40765d073434d9ca6662107f6e9abef509
sha512: 8f22d8e76a45da03485e08d5025081aebe4554f53befdb73354e588f4e604fdb92174307e0e54cabcec544258e86c6a4aed8c759fe5e7be88196e3f486a52fb8
ssdeep: 3072:bC3KXOFkejwGMepHPnO+9j2oADf3Kzki4FEbGGaXdlTKzbTs37ryZMaudBOb7L+s:W2OeIwZep2Cxzk7FEbGGodvsdUBBLTQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154D418ACA873C591D7574A39042CEBA2FB7A43721D6A4970B0B4770E5B21067C2DE37E
sha3_384: a043a2eaff67756df28ae69aea31ccad234279f223cc85b464dc5e1e319c3d6a4cdd7bc5b733f17e61836ba30954161a
ep_bytes: 558bec6aff68d04d410068784e400064
timestamp: 2009-12-23 11:23:32

Version Info:

Comments:
CompanyName: 快快捷桌面秀
FileDescription: 一款桌面辅助美化工具
FileVersion: 2.0.1.1
InternalName: Mac Tool
LegalCopyright: Mac Copyright
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: 快快捷桌面秀
ProductVersion: 2.0.1. 1
SpecialBuild:
Translation: 0x0804 0x04b0

VirTool:Win32/CeeInject!CR also known as:

LionicTrojan.Win32.StartPage.4!c
AVGWin32:Agent-AMKL [Drp]
Elasticmalicious (high confidence)
DrWebTrojan.StartPage1.11288
MicroWorld-eScanGen:Variant.Dropper.13
FireEyeGeneric.mg.8b939e86e1c36182
CAT-QuickHealTrojan.CeeinjectcrRI.S27341433
SkyhighBehavesLike.Win32.Generic.ht
McAfeeGeneric Dropper.sr
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Dropper.13
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005654771 )
AlibabaTrojan:Win32/StartPage.56b9ff28
K7GWTrojan ( 005654771 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.Lq1@a8naCHob
VirITTrojan.Win32.Agent.EQU
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BPJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Startpage-3518
KasperskyTrojan.Win32.StartPage.wwb
BitDefenderGen:Variant.Dropper.13
NANO-AntivirusTrojan.Win32.StartPage.fdpqhs
AvastWin32:Agent-AMKL [Drp]
TencentTrojan.Win32.StartPage.abo
EmsisoftGen:Variant.Dropper.13 (B)
F-SecureTrojan.TR/Dropper.Gen2
ZillyaTrojan.StartPage.Win32.7590
TrendMicroMal_Tap-7
Trapminesuspicious.low.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/StartPage.dnt
VaristW32/Injector.K.gen!Eldorado
AviraTR/Dropper.Gen2
Antiy-AVLTrojan/Win32.StartPage
KingsoftWin32.Trojan.StartPage.wwb
MicrosoftVirTool:Win32/CeeInject.gen!CR
XcitiumTrojWare.Win32.Trojan.Startpage.~wwb@1ukc56
ArcabitTrojan.Dropper.13
ZoneAlarmTrojan.Win32.StartPage.wwb
GDataGen:Variant.Dropper.13
GoogleDetected
AhnLab-V3Win-Trojan/Startpage3.Gen
VBA32BScope.Trojan.StartPage
ALYacGen:Variant.Dropper.13
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Startpage.DHZ
TrendMicro-HouseCallMal_Tap-7
RisingTrojan.Win32.StartPage.odc (CLASSIC)
YandexTrojan.GenAsa!xsQc3Ne8Ymo
IkarusTrojan.Win32.StartPage
MaxSecureTrojan.Malware.1082428.susgen
FortinetW32/Inegery.A!tr
Cybereasonmalicious.6e1c36
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/StartPage.wwb

How to remove VirTool:Win32/CeeInject!CR?

VirTool:Win32/CeeInject!CR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment