Malware

VirTool:Win32/CeeInject!ET removal

Malware Removal

The VirTool:Win32/CeeInject!ET is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject!ET virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine VirTool:Win32/CeeInject!ET?


File Info:

name: 62478FC7AF9F0494938B.mlw
path: /opt/CAPEv2/storage/binaries/63007e97e1d802fe8217ddfb3abed9eb10642011c75582958f9990e9741fde65
crc32: F32E26A6
md5: 62478fc7af9f0494938bcb4782ccc9d2
sha1: 7b9c0d13da3c8f0035a661f571191697825f34ed
sha256: 63007e97e1d802fe8217ddfb3abed9eb10642011c75582958f9990e9741fde65
sha512: 66ff04eba259969a7a3d79f5b785cc0f1254d8e7947933d9242e8b66d4e6ce81869097af02c9cafe8e893e357c7b8108885e8c6e3c81a54158aa5bff8255a7a6
ssdeep: 12288:qaOvHI26VdxhGJJ3Wdsg7NKsiz1+ypx9WBg7Luu:KydxYJUd7KDz1JzHuu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19FE6A3568C7B05BC9E312CF90E7D6A105B775A1607149AE319FEE2FC0E7C2FDA58009A
sha3_384: e09fe08b5308fb02bd315121ff245de738e5e05b1e8be5599548e9c61c766286aa9ff872d0c0fbb533a30f9e499fd356
ep_bytes: e807400000e979feffffcc558bec5756
timestamp: 2011-04-27 15:49:55

Version Info:

0: [No Data]

VirTool:Win32/CeeInject!ET also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen2.27606
CynetMalicious (score: 100)
McAfeeSefnit.p
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.7af9f0
BitDefenderThetaGen:NN.ZexaF.34606.@tZ@aSsGW!ji
VirITTrojan.Win32.Generic.XDK
CyrenW32/Zbot.BU.gen!Eldorado
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.QQD
ClamAVWin.Worm.Kolab-821
KasperskyNet-Worm.Win32.Kolab.aald
BitDefenderGen:Variant.Buzy.3163
NANO-AntivirusTrojan.Win32.Kolab.rbybn
MicroWorld-eScanGen:Variant.Buzy.3163
AvastWin32:Sefnit-AY [Trj]
RisingWorm.Kolab!8.1C4D (CLOUD)
Ad-AwareGen:Variant.Buzy.3163
ComodoMalware@#rkwxkucoxeug
F-SecureTrojan.TR/Downloader.Gen7
ZillyaWorm.Kolab.Win32.5774
McAfee-GW-EditionSefnit.p
FireEyeGeneric.mg.62478fc7af9f0494
EmsisoftGen:Variant.Buzy.3163 (B)
IkarusNet-Worm.Win32.Kolab
GDataGen:Variant.Buzy.3163
JiangminWorm/Kolab.hpi
AviraTR/Downloader.Gen7
Antiy-AVLWorm[Net]/Win32.Kolab
KingsoftWin32.Troj.Generic_a.c.(kcloud)
ArcabitTrojan.Buzy.DC5B
ViRobotWorm.Win32.A.Net-Kolab.1473359
ZoneAlarmNet-Worm.Win32.Kolab.aald
MicrosoftVirTool:Win32/CeeInject.gen!ET
SentinelOneStatic AI – Suspicious PE
AhnLab-V3Worm/Win32.Kolab.C60883
VBA32Worm.Kolab
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
TencentMalware.Win32.Gencirc.10ba2fe7
YandexTrojan.GenAsa!Vs2azOm6p0w
MAXmalware (ai score=80)
FortinetW32/Agent.SF!tr
AVGWin32:Sefnit-AY [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove VirTool:Win32/CeeInject!ET?

VirTool:Win32/CeeInject!ET removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment