Malware

VirTool:Win32/Injector!ER removal instruction

Malware Removal

The VirTool:Win32/Injector!ER is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Injector!ER virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/Injector!ER?


File Info:

crc32: A7377C6F
md5: 4fa0ba4e6191ebe5449a6c12c1d180dd
name: 4FA0BA4E6191EBE5449A6C12C1D180DD.mlw
sha1: b8e6b52a7196310d84a4ba58a6d4044e9012ca72
sha256: bc3c3d453a8851b472c94d38c3f37b9514faaf6a29a2c4973570b3dbe3f1a497
sha512: 58c517ff869711ac3fab9e547935fdcde8609edf2f3209d915673ad3a8227ee6e2eee507efe9efe12fdadd8902226a25c99ce9c1bfd06042685968a525ec821a
ssdeep: 1536:gX/gGkw6G0vuISr//96ARwH7Q+u3co8ACQ1kQh+ZjNeXq4em3KpumGPWZ+E4b3F:gPgGk1yD/9dCQmJyTdcguWMxjWmV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Nebraska
FileVersion: 5.03.0005
CompanyName: CamStudio Open Source Dev Team
ProductName: Kincob's siclike
ProductVersion: 5.03.0005
FileDescription: Bistort' transple munition
OriginalFilename: Nebraska.exe

VirTool:Win32/Injector!ER also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Blocker.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.23
ALYacWorm.Gamarue.gen
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.10728
SangforTrojan.Win32.Kazy.frzt
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.0b5c1ebb
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e6191e
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Wauchos.K
APEXMalicious
AvastWin32:Dropper-gen [Drp]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.chqp
BitDefenderGen:Variant.Jaik.42906
NANO-AntivirusTrojan.Win32.Blocker.cgqhjv
ViRobotTrojan.Win32.Blocker.139264
MicroWorld-eScanGen:Variant.Jaik.42906
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Jaik.42906
SophosMal/Generic-S + Mal/VBZbot-D
ComodoTrojWare.Win32.Injector.AMXL@52ezih
BitDefenderThetaGen:NN.ZevbaF.34050.im0@aWfsoidi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.35JA13
McAfee-GW-EditionRansom-O.a
FireEyeGeneric.mg.4fa0ba4e6191ebe5
EmsisoftGen:Variant.Jaik.42906 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.gnq
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1125067
eGambitGeneric.Downloader
Antiy-AVLTrojan/Generic.ASMalwS.4580A2
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/Injector.gen!ER
ArcabitTrojan.Jaik.DA79A
ZoneAlarmTrojan-Ransom.Win32.Blocker.chqp
GDataGen:Variant.Jaik.42906
TACHYONTrojan/W32.VB-Blocker.139264.B
McAfeeRansom-O.a
MAXmalware (ai score=100)
VBA32Hoax.Blocker
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SPNR.35JA13
YandexTrojan.Blocker!NKA0yVTogmY
IkarusTrojan-Ransom.Blocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBINJECT.SM!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwMAEpsA

How to remove VirTool:Win32/Injector!ER?

VirTool:Win32/Injector!ER removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment