Malware

VirTool:Win32/Obfuscator.AOW removal

Malware Removal

The VirTool:Win32/Obfuscator.AOW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.AOW virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Macau)
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine VirTool:Win32/Obfuscator.AOW?


File Info:

crc32: A6A02DB1
md5: 4e02af097d89a9da4626712ace116951
name: 4E02AF097D89A9DA4626712ACE116951.mlw
sha1: 9852c68c4ca1c042369657fd33b1cf9f8a90f325
sha256: 9de386b80e7445654a7f5b7a49648ed1efc319a3fbce1e8e91dcd94499998eb6
sha512: 9114ae9ed41d401a2e8b08f20a0785e7eea1b9421ac68bec79c90a5336d4bd70f8f9fcfd7c0fb7cd984ab16a4e362c462fb26b828c8e85775faf9ab03a6fd020
ssdeep: 6144:6sATeHUCwiQOW8bFX/+BTKkWiXdi87jIKXBOIWJoWurp:yeHvwiQgbFX/mT/XIkBBgyrp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Fetid xa9 1916
InternalName: Indecision
FileVersion: 120, 106, 141, 185
CompanyName: GotAllMedia
ProductName: Enveloping Expansionary
FileDescription: Dramatic
OriginalFilename: Euro.exe

VirTool:Win32/Obfuscator.AOW also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.TeslaCrypt.WR4
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.39019
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Waldek.0da644d0
K7GWTrojan ( 004d41c61 )
K7AntiVirusTrojan ( 004d41c61 )
CyrenW32/Trojan.WTCA-1633
ESET-NOD32Win32/Filecoder.TeslaCrypt.D
APEXMalicious
AvastWin32:TeslaCrypt-BH [Trj]
KasperskyTrojan.Win32.Waldek.rxr
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Yakes.dvrmpl
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.114c7af3
Ad-AwareTrojan.Cripack.Gen.1
SophosML/PE-A + Mal/Tinba-AB
ComodoMalware@#dbj25czxmlse
BitDefenderThetaGen:NN.ZexaF.34628.tq3@aiugMYkH
VIPRETrojan.Win32.Generic!BT
TrendMicroCryp_HpMyApp
McAfee-GW-EditionTeslaCrypt!4E02AF097D89
FireEyeGeneric.mg.4e02af097d89a9da
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Yakes.xws
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1132448
eGambitGeneric.Malware
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.AOW
ArcabitTrojan.Cripack.Gen.1
AegisLabTrojan.Win32.Waldek.4!c
GDataTrojan.Cripack.Gen.1
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeTeslaCrypt!4E02AF097D89
MAXmalware (ai score=100)
VBA32Trojan.Yakes
MalwarebytesTrojan.CryptoLocker
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_HpMyApp
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.Yakes!kXVqM1EWM7U
IkarusTrojan.Win32.Yakes
FortinetW32/Deshacop.XO!tr
AVGWin32:TeslaCrypt-BH [Trj]
Qihoo-360HEUR/QVM07.1.024D.Malware.Gen

How to remove VirTool:Win32/Obfuscator.AOW?

VirTool:Win32/Obfuscator.AOW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment