Malware

VirTool:Win32/Obfuscator.ADU information

Malware Removal

The VirTool:Win32/Obfuscator.ADU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.ADU virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

How to determine VirTool:Win32/Obfuscator.ADU?


File Info:

crc32: 6428428F
md5: bdb93f28da987675828ac36e2fcab68f
name: BDB93F28DA987675828AC36E2FCAB68F.mlw
sha1: bdcce8fa987b2d5d72e2258f23cabb2a27aa1adb
sha256: 7bdb83171853f698da2ce1238256b65d589a3c67c511885b77cb67218b6d4adb
sha512: e42d439cad8ad3877dc4d8b62f00f600a4f994a408da6a3dce19f601e5fd272ae5556fbb03fd126f4004e05f7ccae1886d8b23c57710f85359d820f4617e5dd9
ssdeep: 6144:YyA0RfgwyipvbYA+YC1GAiL9GvvqydpRlbydJ3ArV81iug6U7v:YkRfgwyipzYA+YwvJfydlA27g77v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/Obfuscator.ADU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Multi.911
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.2962
SangforHacktool.Win32.Obfuscator.ADU
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaVirTool:Win32/Obfuscator.8d42eabe
K7GWRiskware ( 0040eff71 )
ESET-NOD32a variant of Win32/Injector.AAKR
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Multi.cvknqk
ViRobotTrojan.Win32.A.Bublik.870912
SophosMal/Generic-S
ComodoMalware@#2saloq43tdg15
BitDefenderThetaAI:Packer.16D7F9FA19
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-Zbot-FAGP!BDB93F28DA98
FireEyeGeneric.mg.bdb93f28da987675
AviraTR/Obfuscate.adu.1
eGambitGeneric.Malware
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.ADU
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Lmirhack.C7533
McAfeePWS-Zbot-FAGP!BDB93F28DA98
MAXmalware (ai score=100)
VBA32Trojan.Chisburg
MalwarebytesMalware.AI.3734395387
PandaTrj/Agent.MIZ
RisingRansom.Blocker!8.12A (CLOUD)
IkarusTrojan-Ransom.Blocker
FortinetW32/Generic.AC.2552C0!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Trojan.Generic.HwUByscA

How to remove VirTool:Win32/Obfuscator.ADU?

VirTool:Win32/Obfuscator.ADU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment