Malware

VirTool:Win32/CeeInject!EG removal

Malware Removal

The VirTool:Win32/CeeInject!EG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject!EG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempted to write directly to a physical drive
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine VirTool:Win32/CeeInject!EG?


File Info:

name: AFDACADAC8580E2EF1FE.mlw
path: /opt/CAPEv2/storage/binaries/dbd6aa1edfba0b33fa677dd9c64e96bca84967ef06416d3c0be781394758fb55
crc32: 5DD1C578
md5: afdacadac8580e2ef1fe4ef4cf34813a
sha1: 1043400035b8356ef531eefca3cd66a832dd25ec
sha256: dbd6aa1edfba0b33fa677dd9c64e96bca84967ef06416d3c0be781394758fb55
sha512: f636b3bde359e8d6279b232fc8def76c33d7c7479c567c5ea0b1a5658fae024497bfadc130730903c141525c6bce6315bd76a00e332497ed479af87f7cbe1290
ssdeep: 3072:N4/L/JDPaUSS3JfqhdK4TqbFjvnO5+ficHmKs8KWlqEV2v4hE3SuNzUlyTEf5A:e/bJ/Df1FTOw/HmV8R4EV04hUtzk6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136648C0DA111C4F7DC1509B4E018FA156966AF30CAADC67B67DD378DBDF2283E892893
sha3_384: 72e89f8a675a97be4a5daa29be122fd2aab6f6b8e8b7dadc9bd30d5c5c8ad7cde0592881ac3a4e82e7042096cc2e19be
ep_bytes: e8cc2a0000e916feffff6a0c6850cd40
timestamp: 2011-05-02 22:00:12

Version Info:

FileDescription: Example MSVC Application
FileVersion: 1,0,0,0
InternalName: Example
LegalCopyright:
OriginalFilename: Example.exe
ProductName: Example MSVC Application
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04b0

VirTool:Win32/CeeInject!EG also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Onuni.4!c
Elasticmalicious (moderate confidence)
DrWebBackDoor.Siggen.28213
MicroWorld-eScanGen:Trojan.Heur.tq0@!77ONuni
FireEyeGeneric.mg.afdacadac8580e2e
McAfeeArtemis!AFDACADAC858
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/CeeInject.02dcfc2f
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Heur.E81CBF
BitDefenderThetaAI:Packer.38ADB6821C
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.GCW
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.BSOD.gen
BitDefenderGen:Trojan.Heur.tq0@!77ONuni
NANO-AntivirusTrojan.Win32.FakeAV.ctbue
AvastWin32:GenMalicious-KOR [Trj]
EmsisoftGen:Trojan.Heur.tq0@!77ONuni (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen8
VIPREGen:Trojan.Heur.tq0@!77ONuni
TrendMicroTROJ_GEN.R002C0DEO23
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.high.ml.score
SophosTroj/Inject-STI
IkarusTrojan-Dropper.SuspectCRC
JiangminWorm/AutoRun.aatu
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.ZPACK.Gen8
Antiy-AVLTrojan/Win32.TDSS
MicrosoftVirTool:Win32/CeeInject.gen!EG
ZoneAlarmHEUR:Trojan.Win32.BSOD.gen
GDataGen:Trojan.Heur.tq0@!77ONuni
GoogleDetected
AhnLab-V3Trojan/Win.Injection.C5432601
VBA32BScope.Backdoor.Ruskill.2921
ALYacGen:Trojan.Heur.tq0@!77ONuni
MAXmalware (ai score=80)
MalwarebytesCrypt.Trojan.Malicious.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0DEO23
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.WDH!tr
AVGWin32:GenMalicious-KOR [Trj]
Cybereasonmalicious.ac8580
DeepInstinctMALICIOUS

How to remove VirTool:Win32/CeeInject!EG?

VirTool:Win32/CeeInject!EG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment