Malware

VirTool:Win32/Obfuscator.NI (file analysis)

Malware Removal

The VirTool:Win32/Obfuscator.NI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.NI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VirTool:Win32/Obfuscator.NI?


File Info:

name: 38F55F74949894BAE32C.mlw
path: /opt/CAPEv2/storage/binaries/d6afc08ec342c5d3b6c8ffb65926a2c41f97ff2b515b2505d6a1f0f306b26186
crc32: 46B58808
md5: 38f55f74949894bae32cf697206784f7
sha1: a90436da36f393f2db113ed3f44c86d2973922d3
sha256: d6afc08ec342c5d3b6c8ffb65926a2c41f97ff2b515b2505d6a1f0f306b26186
sha512: af1ff7aef530f1944d419d06a4d1ae16a6e4d24afff39644055639ca7a4db883a0e88bb48cd4e7273240fc29825f51053e39f1f0239a1d9496f5c697c9159bf0
ssdeep: 768:lZ4s2dMw8rorfnmKUMLZNDn/QlgmFIkCd+hNFIktcM9ea5PnOYn6zykNspK6D8L6:l+s4hANDnVJbBvmO0NMm9iCXOjD5tx9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19553B62B734A1826DB18A2397267C7E719E3748A4B4F1A832778637EDD64F102C15B63
sha3_384: 1674636521e377cbd0bc73d7ce252596cccc8da2a9b7d2913dfd0a83ba7b5aae0058b1469b7e7b53230f8abc2ad5e0db
ep_bytes: 68b0114000e8eeffffff000000000000
timestamp: 2010-12-25 14:15:51

Version Info:

Translation: 0x0409 0x04b0
ProductName: 8765VBRUN
FileVersion: 1.28
ProductVersion: 1.28
InternalName: VkkMu9998
OriginalFilename: VkkMu9998.exe

VirTool:Win32/Obfuscator.NI also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li7E
AVGWin32:AutoRun-BSJ [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.719
FireEyeGeneric.mg.38f55f74949894ba
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.kt
ALYacGen:Variant.Symmi.719
Cylanceunsafe
VIPREGen:Variant.Symmi.719
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:Win32/vobfus.1030
K7GWTrojan ( 001e96331 )
K7AntiVirusTrojan ( 001e96331 )
BaiduWin32.Worm.AutoRun.cj
VirITTrojan.Win32.Shiru.AY
SymantecW32.SillyFDC
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.XY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Vobfus-9806879-0
KasperskyWorm.Win32.VBNA.brml
BitDefenderGen:Variant.Symmi.719
NANO-AntivirusTrojan.Win32.VBKrypt.cmxska
AvastWin32:AutoRun-BSJ [Trj]
TencentWorm.Win32.VBNA.hd
TACHYONTrojan/W32.VB-VBKrypt.61440.D
SophosMal/SillyFDC-I
F-SecureTrojan:W32/Vbkrypt.D
DrWebTrojan.MulDrop4.51964
TrendMicroWORM_VOBFUS.SMIA
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Symmi.719 (B)
IkarusTrojan-Dropper
JiangminWorm/VBNA.gxxv
VaristW32/VB.BT.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftVirTool:Win32/Obfuscator.NI
XcitiumTrojWare.Win32.VB.X@2i170u
ArcabitTrojan.Symmi.719
ViRobotWorm.Win32.A.VBNA.61440.DC
ZoneAlarmWorm.Win32.VBNA.brml
GDataGen:Variant.Symmi.719
GoogleDetected
AhnLab-V3Trojan/Win32.VB.R2205
McAfeeDownloader-CJX.gen.o
MAXmalware (ai score=82)
VBA32SScope.Trojan.VBRA.2842
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingWorm.Autorun!1.99E9 (CLASSIC)
YandexTrojan.VBKrypt.Gen.8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.AGW!tr
BitDefenderThetaAI:Packer.E5B86E9320
Cybereasonmalicious.494989
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.555452b9

How to remove VirTool:Win32/Obfuscator.NI?

VirTool:Win32/Obfuscator.NI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment