Malware

VirTool:Win32/Obfuscator.GQ malicious file

Malware Removal

The VirTool:Win32/Obfuscator.GQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.GQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine VirTool:Win32/Obfuscator.GQ?


File Info:

crc32: C782E510
md5: 9219e2cfcc64ccde2d8de507538b9991
name: rootkit.ex1
sha1: 181e59600d057dc6b31a3b19d7f4f75301a3425e
sha256: 5af3fd53aea5e008d8725c720ea0290e2e0cd485d8a953053ccf02e5e81a94a0
sha512: 81aa2fbde8567f4a3446d56a8fec8b346f9c4093f5baa32db4069644ad3fec64c6c2d749173557e5247144b92fa12ddb14de55ca3687867d4aea4c37124c9f54
ssdeep: 1536:m+6OXCt1SXBW0bBaKLXDduSOxqEDX0+G3L6f2X4ZmfwhRYE:/6Y41aBNbBBXkSCPDMV4hmE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: notepad
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
OriginalFilename: notepad.exe
FileDescription: notepad
Translation: 0x0409 0x0000

VirTool:Win32/Obfuscator.GQ also known as:

BkavW32.CreateRookit.Trojan
MicroWorld-eScanTrojan.Generic.3256916
FireEyeGeneric.mg.9219e2cfcc64ccde
CAT-QuickHealTrojan.Generic
McAfeeArtemis!9219E2CFCC64
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.mmu (mx-v)
SangforMalware
K7AntiVirusTrojan ( 0040f5651 )
BitDefenderTrojan.Generic.3256916
K7GWTrojan ( 0040f5651 )
Cybereasonmalicious.fcc64c
TrendMicroTROJ_RUSTOCK.NCT
F-ProtW32/MalwareF.XIUM
TotalDefenseWin32/BOFCrypt.D
APEXMalicious
AvastWin32:Zbot-LYA [Trj]
ClamAVWin.Trojan.Lancafdo-1
GDataTrojan.Generic.3256916
KasperskyHEUR:Trojan.Win32.Generic
AlibabaVirTool:Win32/Obfuscator.f7a48b12
NANO-AntivirusTrojan.Win32.Annoy.itmq
ViRobotBackdoor.Win32.S.Blakken.76288
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Generic!8.C3 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Bancos-E
ComodoMalware@#g5iwb3whzv24
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebTrojan.Winlock.1110
ZillyaBackdoor.Blakken.Win32.3
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ipamor.lc
MaxSecureTrojan.Malware.2255689.susgen
Trapminemalicious.high.ml.score
CMCBackdoor.Win32.Blakken!O
EmsisoftTrojan.Generic.3256916 (B)
IkarusTrojan-Spy.Win32.Zbot
CyrenW32/Risk.RDOO-2190
JiangminBackdoor/Blakken.ab
WebrootW32.Trojan.Trojan.gen
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Blakken
MicrosoftVirTool:Win32/Obfuscator.GQ
ArcabitTrojan.Generic.D31B254
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Zbot.R14737
Acronissuspicious
VBA32Malware-Cryptor.Win32.Vals.22
ALYacTrojan.Generic.3256916
TACHYONTrojan/W32.Agent.76288.MY
Ad-AwareTrojan.Generic.3256916
MalwarebytesTrojan.Injector.dKVU
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HCD
TrendMicro-HouseCallTROJ_RUSTOCK.NCT
TencentWin32.Trojan.Generic.Hprl
YandexTrojan.Obfuscated!Xy/s40KWD08
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.DT!tr
BitDefenderThetaGen:NN.ZexaF.34090.eqW@aa!mV3f
AVGWin32:Zbot-LYA [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.015

How to remove VirTool:Win32/Obfuscator.GQ?

VirTool:Win32/Obfuscator.GQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment