Malware

VirTool:Win32/Injector!BQ removal guide

Malware Removal

The VirTool:Win32/Injector!BQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Injector!BQ virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VirTool:Win32/Injector!BQ?


File Info:

name: 2EB690304F3C2106ED3E.mlw
path: /opt/CAPEv2/storage/binaries/0bb5dcbdb314183373f217c1b4b821e50c9933e492ea627aea1f1cf715b4e869
crc32: FFDA2A1D
md5: 2eb690304f3c2106ed3e1c6728dcbb0c
sha1: d9e8c80402f5c2ed57cdd38855047c49f157c6e4
sha256: 0bb5dcbdb314183373f217c1b4b821e50c9933e492ea627aea1f1cf715b4e869
sha512: 548f0e4be72c9ec20b1530b2847cfdf9bf05ecfc7ae9424994babee5c2bef56f4577ff3388db36f5c619592ca1aad6e9988c4a2cfe51234438c56a41daca465a
ssdeep: 3072:uGwPsm1VrwxOsf0juzv8j4P1Hr6krr4IEhh:uG/iVkO20SFgBhh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0D30217D7DC72CEC8796DBC78E6EA20446F46C51200E3421C95DB3BFAF75128E8528A
sha3_384: 6b271de1f57e59cc3cee43a5cd702232dc262caa2db8c81630f7a2b81d8162a51e7e6b72be899f2058afc6cdb96281d5
ep_bytes: 33c0a3092c4c006800000000588bd081
timestamp: 2004-06-16 01:53:16

Version Info:

0: [No Data]

VirTool:Win32/Injector!BQ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Packed.20771
MicroWorld-eScanGen:Variant.Babar.72995
McAfeeW32/Etap.a.gen
ZillyaTrojan.Shiz.Win32.280
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 005068aa1 )
K7GWSpyware ( 005068aa1 )
CrowdStrikewin/malicious_confidence_100% (D)
ESET-NOD32Win32/Spy.Shiz.NBX
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Babar.72995
NANO-AntivirusTrojan.Win32.Crypted.vryyc
AvastWin32:Downloader-JFW [Trj]
EmsisoftGen:Variant.Babar.72995 (B)
VIPREGen:Variant.Babar.72995
TrendMicroBKDR_SHIZ.SMA
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.2eb690304f3c2106
SophosML/PE-A
IkarusBackdoor.Win32.Shiz
GDataGen:Variant.Babar.72995
JiangminBackdoor/Shiz.avs
MAXmalware (ai score=83)
Antiy-AVLTrojan[Backdoor]/Win32.Shiz
Kingsoftmalware.kb.a.1000
XcitiumBackdoor.Win32.Shiz.NBXA@4k7wop
ArcabitTrojan.Babar.D11D23
ViRobotBackdoor.Win32.A.Shiz.216576
MicrosoftVirTool:Win32/Injector.gen!BQ
GoogleDetected
AhnLab-V3Backdoor/Win32.Shiz.R72562
ALYacGen:Variant.Babar.72995
VBA32Malware-Cryptor.2LA.gen
MalwarebytesMalware.AI.339783506
TrendMicro-HouseCallBKDR_SHIZ.SMA
RisingHackTool.Injector!8.1E2 (TFE:1:RaY0BKZLfqS)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Shiz.gen
FortinetW32/Shiz.X!tr
AVGWin32:Downloader-JFW [Trj]
Cybereasonmalicious.402f5c

How to remove VirTool:Win32/Injector!BQ?

VirTool:Win32/Injector!BQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment