Malware

About “VirTool:Win32/Obfuscator.CAM” infection

Malware Removal

The VirTool:Win32/Obfuscator.CAM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.CAM virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/Obfuscator.CAM?


File Info:

crc32: EEDF5C5B
md5: af4eee51984d9dcd714b65c8defc9b66
name: AF4EEE51984D9DCD714B65C8DEFC9B66.mlw
sha1: 44587d2e493a165ca7ca9af7f353107d008426b8
sha256: a34444775f94f6e915a6c1e600f8ef02668bf89a4cddffc899c8069c0f62c613
sha512: cdf951ac8cadf2afe5007b9066cb5742a1f27082a5a9801228323683610e9020cf1b022c26187df0a85e9c98cb0006688b44173aade753c0ba27ff0a2c28b689
ssdeep: 6144:mHgpoHsQZh45j7zZYWMqPR3PiTkktA3yb4F:mApoMPj7zTMqPR3PiTkCb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: zefzef.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: zefzef.exe
Translation: 0x040c 0x04b0

VirTool:Win32/Obfuscator.CAM also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1984d9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.HCNVGAU
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.Obfuscate.evkrma
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentWin32.Trojan.Ransom.Loru
Ad-AwareTrojan.BRMon.Gen.4
SophosML/PE-A + Troj/Shiotob-BJ
ComodoMalware@#3utc873z8qg0a
BitDefenderThetaGen:NN.ZexaF.34692.pu3@aGAIg7le
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_HPISDA.SM
McAfee-GW-EditionBehavesLike.Win32.VBobfus.dc
FireEyeGeneric.mg.af4eee51984d9dcd
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Obfuscate.ertvk
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22CE2B4
MicrosoftVirTool:Win32/Obfuscator.CAM
GDataTrojan.BRMon.Gen.4
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
McAfeeTrojan-FJNQ!AF4EEE51984D
MAXmalware (ai score=100)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_HPISDA.SM
RisingHackTool.Obfuscator!8.236 (CLOUD)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.173F4!tr
AVGWin32:Malware-gen

How to remove VirTool:Win32/Obfuscator.CAM?

VirTool:Win32/Obfuscator.CAM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment