Malware

VirTool:Win32/Obfuscator.KH malicious file

Malware Removal

The VirTool:Win32/Obfuscator.KH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.KH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs

How to determine VirTool:Win32/Obfuscator.KH?


File Info:

crc32: 3834A1F4
md5: bc91c089315c35ce7ec7efef2f0d84d6
name: BC91C089315C35CE7EC7EFEF2F0D84D6.mlw
sha1: 4a20c6dcfe1cced47d7ee717f66266778d76d1ec
sha256: 481d67ebd05d7ff566c9fb3fba76d9d0a28420d88b1a010a4727f0fbb151e152
sha512: b83e2af33623baef3607279e59ff70358a03fb9eefe6e325802f2296d10ad5cd161d70fa462b49c8b72f8a86e17957857dfcb1b629b35b0133de8f211f7d76bd
ssdeep: 6144:fAt5FuFGQHoUORMn59jVe2KzYEOr9kPg8/1Fhq:g5wFGQHoUOynjVeBzYW/1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2000-
Web: kjtlael
FileVersion: 9.36.11
Author: rsumfoq
CompanyName: sysiv
File Description: wbxv
Comments: gdxmycn
Internal Name: knwr
Translation: 0x0409 0x04b0

VirTool:Win32/Obfuscator.KH also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005223351 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Generic.4733074
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.8491
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/PinkBlocker.1af3cc85
K7GWTrojan ( 005223351 )
Cybereasonmalicious.9315c3
SymantecTrojan.Zbot!gen9
ESET-NOD32Win32/LockScreen.UK
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.PinkBlocker.clc
BitDefenderTrojan.Generic.4733074
NANO-AntivirusTrojan.Win32.Winlock.bdusf
MicroWorld-eScanTrojan.Generic.4733074
TencentWin32.Trojan.Pinkblocker.Pijp
Ad-AwareTrojan.Generic.4733074
SophosML/PE-A + Mal/FakeAV-BW
ComodoMalCrypt.Indus!@1qrzi1
BitDefenderThetaAI:Packer.B119D3FD1F
VIPRETrojan.Win32.Kryptik.fte (v)
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
FireEyeGeneric.mg.bc91c089315c35ce
EmsisoftTrojan.Generic.4733074 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/PinkBlocker.amg
AviraTR/Crypt.XPACK.Gen8
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.1887F77
MicrosoftVirTool:Win32/Obfuscator.KH
AegisLabTrojan.Win32.PinkBlocker.j!c
GDataTrojan.Generic.4733074
Acronissuspicious
McAfeeArtemis!BC91C089315C
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Tinba
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.89 (RDML:YX90sMXX8aD+U8r/v7bkjw)
IkarusWorm.Win32.Ramnit
FortinetW32/Krypt.A!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove VirTool:Win32/Obfuscator.KH?

VirTool:Win32/Obfuscator.KH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment