Malware

What is “VirTool:Win32/CeeInject!DZ”?

Malware Removal

The VirTool:Win32/CeeInject!DZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject!DZ virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • A possible cryptomining command was executed
  • Anomalous binary characteristics

Related domains:

btcg.lolniggawhyuhighth0.com

How to determine VirTool:Win32/CeeInject!DZ?


File Info:

crc32: F032ACE7
md5: 6febb36e8e62ead1a1cebca2acc950a5
name: 6FEBB36E8E62EAD1A1CEBCA2ACC950A5.mlw
sha1: b32ca6ec9fbcc1e0199e04c61b448adf39857a4f
sha256: d6c250eb4994a4e51b00e2f6d34f69afab0026c23269cdfe5b835af404ed3100
sha512: 9acb92b91f17e393f3d34bc650fb86f86de61831980dda0835c5734882ebe9a9f5267aea3922d160717ff16d8b875c5a1c9421d19424acd325766691b4cd8a2a
ssdeep: 6144:rq8sKN1eXp2Vq962un3frNNwrBk1fKl2pcuXtfXfSWZ4E:LDeXp2VYpunvsrBErpcqBSUx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2011
InternalName: Cwork
FileVersion: 1, 0, 0, 1
CompanyName: TensilCodes
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Cwork
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: worker for TensilCrypt
OriginalFilename: Cwork.exe
Translation: 0x0409 0x04b0

VirTool:Win32/CeeInject!DZ also known as:

K7AntiVirusTrojan ( 004ebf101 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.872
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Lethic.Gen.4
CylanceUnsafe
ZillyaWorm.Palevo.Win32.71121
CrowdStrikewin/malicious_confidence_70% (W)
K7GWTrojan ( 004ebf101 )
Cybereasonmalicious.e8e62e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.IUS
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Worm.Palevo-31158
KasperskyP2P-Worm.Win32.Palevo.drph
BitDefenderTrojan.Lethic.Gen.4
NANO-AntivirusTrojan.Win32.Palevo.tpqqr
ViRobotWorm.Win32.A.P2P-Palevo.108032.I
MicroWorld-eScanTrojan.Lethic.Gen.4
TencentMalware.Win32.Gencirc.10bad8cb
Ad-AwareTrojan.Lethic.Gen.4
SophosML/PE-A + Mal/Inject-CEE
ComodoWorm.Win32.P2P-Worm.Palevo.kfpr@4xpur6
BitDefenderThetaGen:NN.ZexaF.34266.oq0@aO4GKgni
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.6febb36e8e62ead1
EmsisoftTrojan.Lethic.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1115251
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1504F4
MicrosoftVirTool:Win32/CeeInject.gen!DZ
ArcabitTrojan.Lethic.Gen.4
GDataTrojan.Lethic.Gen.4
TACHYONTrojan-Spy/W32.ZBot.243200.O
AhnLab-V3Worm/Win32.Palevo.R20077
McAfeeW32/IRCBot.gen.cm
MAXmalware (ai score=80)
VBA32Worm.Palevo
MalwarebytesMalware.AI.526624797
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.98 (RDML:Bf2I21U4dYi2Mi60+F20ng)
YandexTrojan.GenAsa!peTtwGNYy4U
IkarusP2P-Worm.Win32.Palevo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.IUS!tr
AVGWin32:Trojan-gen

How to remove VirTool:Win32/CeeInject!DZ?

VirTool:Win32/CeeInject!DZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment