Malware

Should I remove “VirTool:Win32/Obfuscator.EK”?

Malware Removal

The VirTool:Win32/Obfuscator.EK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.EK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs

How to determine VirTool:Win32/Obfuscator.EK?


File Info:

crc32: 02790429
md5: cf271dc2e8cd5d1f963d4a2c1f9c41b9
name: RusSSCreator.exe
sha1: d5cb2a97927b51237c468eb618e764c764919ba2
sha256: 7cbfad814c7d2bbef5c3ae70d86b9e5e5297ef1d57c8c7353ee8193f2041df95
sha512: 8b7c65a54ef5c7e8dab4d984596c3966aa3b4ad9e03a58ed6caed96d04855bd72ac29b7f073225b1496aa7a8ce769d52e7f1e79f7d92cfc2be20466e29c95417
ssdeep: 49152:uqqhXtPTs1yXdkUk7DHFseBRO/gBSL2EAy53NHt:5qhdzXyDDHFsIBSSY59N
type: PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive

Version Info:

InternalName:
FileVersion:
CompanyName: Sergeev. A.V.
Comments: This installation was built with Inno Setup: http://www.innosetup.com
ProductName:
ProductVersion:
FileDescription: Russian Screensaver Creator Setup
OriginalFilename:
Translation: 0x0409 0x04e4

VirTool:Win32/Obfuscator.EK also known as:

McAfeeArtemis!CF271DC2E8CD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
F-ProtW32/Troj_Obfusc.Z.gen!Eldorado
SymantecTrojan.Gen.2
AvastWin32:Malware-gen
AlibabaVirTool:Win32/Obfuscator.085e5cf5
NANO-AntivirusRiskware.Win32.Obfuscate.dyzmlr
ViRobotTrojan.Win32.Z.Obfuscate.1995000
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Win32.Generic.187463D0 (C64:YzY0OuB/Uz52MrJ+)
ComodoTrojWare.Win32.PkdMorphine.~AN@1l4q0o
F-SecureTrojan.TR/Obfuscate.1995000
DrWebProgram.Monitor.3361
TrendMicroMal_Mlwr-13
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
Trapminesuspicious.low.ml.score
SophosMal/EncPk-ZE
CyrenW32/Troj_Obfusc.Z.gen!Eldorado
WebrootW32.Malware.Gen
AviraTR/Obfuscate.1995000
MicrosoftVirTool:Win32/Obfuscator.EK
ESET-NOD32a variant of Win32/Packed.GHFProtector.A suspicious
TrendMicro-HouseCallMal_Mlwr-13
YandexPacked/Morphine
eGambitUnsafe.AI_Score_61%
FortinetPossibleThreat
BitDefenderThetaAI:Packer.C881AC5F20
AVGWin32:Malware-gen

How to remove VirTool:Win32/Obfuscator.EK?

VirTool:Win32/Obfuscator.EK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment