Malware

VirTool:Win32/CeeInject!HL information

Malware Removal

The VirTool:Win32/CeeInject!HL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/CeeInject!HL virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

e-lako.com
kaleoarkansas.org
mdcharity.org
dlhrecording.com

How to determine VirTool:Win32/CeeInject!HL?


File Info:

crc32: A6400F74
md5: 8f2861758d0856e7ab5daede1fbf1654
name: 8F2861758D0856E7AB5DAEDE1FBF1654.mlw
sha1: 812ac73fb156bc4fdd16af3c3fbf14eafdd2031a
sha256: 40a19e2533ca309b7024b309cd3bc5b3e01f4ed6e89211140fc48526fd28f31d
sha512: b35773c6117d5ccb4f0e138772b1821d5a24d89addf6934cee330540bf44845b7682e28c0ec5aea5e3372596908927e7c806e283bd3a96b55f411f3151a8633e
ssdeep: 1536:y2tsztbENeFHik8D5GoXEQI1t4oNvKH95dAuxAyvx:Bt0ontTUQQdNqRnxAy
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/CeeInject!HL also known as:

BkavW32.AIDetectVM.malware5
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.157825
FireEyeGeneric.mg.8f2861758d0856e7
CAT-QuickHealTrojan.Ransom.A
McAfeePWS-Zbot-FASN!8F2861758D08
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Kazy.157825
Cybereasonmalicious.58d085
SymantecTrojan.Ransomlock!g41
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyHEUR:Trojan.Win32.Generic
RisingMalware.Undefined!8.C (TFE:1:c9mA0jfKVrG)
Ad-AwareGen:Variant.Kazy.157825
EmsisoftGen:Variant.Kazy.157825 (B)
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebTrojan.PWS.Siggen2.59299
InvinceaML/PE-A + Troj/Agent-AJFK
McAfee-GW-EditionBehavesLike.Win32.Downloader.kc
SophosTroj/Agent-AJFK
IkarusVirus.Win32.CeeInject
JiangminTrojan.Generic.hyuv
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=81)
MicrosoftVirTool:Win32/CeeInject.gen!HL
ArcabitTrojan.Kazy.D26881
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Kazy.157825
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R58705
Acronissuspicious
ALYacGen:Variant.Kazy.157825
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.AGCB
YandexTrojan.GenAsa!FIRs/pb2PWU
SentinelOneStatic AI – Suspicious PE
BitDefenderThetaAI:Packer.22643BD31E
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.44A7.Malware.Gen

How to remove VirTool:Win32/CeeInject!HL?

VirTool:Win32/CeeInject!HL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment