Malware

VirTool:Win32/Obfuscator.KU (file analysis)

Malware Removal

The VirTool:Win32/Obfuscator.KU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.KU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VirTool:Win32/Obfuscator.KU?


File Info:

name: C431C3B51BFA5F0A4B26.mlw
path: /opt/CAPEv2/storage/binaries/d43aa02ba0ff42f06bc8c390f301e060dcad8ab180305c853d7b268c2c9b1b5d
crc32: 0FFEBE5B
md5: c431c3b51bfa5f0a4b26120a9c99984d
sha1: 076e8552208d30c147570e90bdb9f2518218da55
sha256: d43aa02ba0ff42f06bc8c390f301e060dcad8ab180305c853d7b268c2c9b1b5d
sha512: e99c88517ec9982f07ab2d106b77ff00b89b16c121d97b4c97acaf81b26dcbafcefb9183e25cc621d70fc42ad5ab4d09cfccce0725a56be1c698adaeb0b08970
ssdeep: 3072:zl3/WNAfcmnFgPWO2FIjOsA8YNXuB2bnxs5q8YURx8icN31WV3ScApAf+wS:MNAfcmF+YI6Teqs5qdURxdi3LdAM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C124120BBCB50724F4BA433029934BE9DC9CB511025E4767804E6AD629B133FFA76DA7
sha3_384: f7d41732bf32535dc593470a2b837ad0d87fa0a1292c0ba70a83527b13f9c9b92711cf748ef39d592da15b9b242c6502
ep_bytes: 558bec83ec2856576a4de891f5ffff8b
timestamp: 2010-07-03 16:02:20

Version Info:

FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
ProductVersion: 6.1.7600.16385
CompanyName: Microsoft Corporation
FileDescription: Приложение служб и контроллеров
InternalName: services.exe
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: services.exe.mui
ProductName: Операционная система Microsoft® Windows®
Translation: 0x0419 0x04b0

VirTool:Win32/Obfuscator.KU also known as:

BkavW32.Common.B90CD1BE
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Kazy.3060
FireEyeGeneric.mg.c431c3b51bfa5f0a
ALYacGen:Variant.Kazy.3060
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.29671
SangforSuspicious.Win32.Save.a
AlibabaVirTool:Win32/Obfuscator.f8a4e792
Cybereasonmalicious.51bfa5
VirITTrojan.Win32.Crypt.AERH
CyrenW32/Risk.WOSN-6187
SymantecPacked.Generic.339
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.Tiny.NAI
APEXMalicious
ClamAVWin.Trojan.Agent-906507
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.3060
NANO-AntivirusTrojan.Win32.SpyEyes.bruyv
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Spyeyes.Swaj
Ad-AwareGen:Variant.Kazy.3060
SophosMal/Generic-R + Mal/ZBot-BT
ComodoMalware@#1o86kxxsfqtjx
DrWebBackDoor.Spy.700
VIPREGen:Variant.Kazy.3060
TrendMicroTROJ_SPYEYES.H
McAfee-GW-EditionPWS-Zbot.gen.da
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Kazy.3060 (B)
IkarusTrojan.Crypt
WebrootW32.Bumat.Gen
AviraTR/Spy.Zbot.hak
MAXmalware (ai score=100)
KingsoftWin32.VirInstaller.Tiny.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.KU
ArcabitTrojan.Kazy.DBF4
ViRobotTrojan.Win32.SpyEyes.223880
GDataGen:Variant.Kazy.3060
CynetMalicious (score: 100)
McAfeePWS-Zbot.gen.da
VBA32Heur.Trojan.Hlux
MalwarebytesMalware.Heuristic.1008
TrendMicro-HouseCallTROJ_SPYEYES.H
RisingTrojan.Generic@AI.90 (RDML:Trj1RnRz4Z3QFFYgmW5QqQ)
YandexTrojan.DR.Tiny!tiGxt2RgWVg
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AP.42280
BitDefenderThetaGen:NN.ZexaF.34742.nq1@aKFCzyik
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove VirTool:Win32/Obfuscator.KU?

VirTool:Win32/Obfuscator.KU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment