Malware

VirTool:Win32/Obfuscator.NZ malicious file

Malware Removal

The VirTool:Win32/Obfuscator.NZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.NZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine VirTool:Win32/Obfuscator.NZ?


File Info:

name: C94CF67F2977E861E02C.mlw
path: /opt/CAPEv2/storage/binaries/9e1c82dc1efe851f36163299a68467627361c12230e5505c2108062bede03ca4
crc32: 0F77F60E
md5: c94cf67f2977e861e02cf42a007c8ebc
sha1: d4e6b73766667ffde48bc90e9eeb8a5fe46b5601
sha256: 9e1c82dc1efe851f36163299a68467627361c12230e5505c2108062bede03ca4
sha512: e1dfdae4a64511748c70edf1bde30100e2d6fd4552fc407124db3ed8a1d49f0613f207a4ddfb483b7f28aaab3fce47b8640eefae43d9c01dcd05af7cc47ccf19
ssdeep: 6144:uP2bvKyCPkpBYR/z1Oo0nU1gjnKMoH+7MksPH9mgFrSJH:uP2bvO8PE/Ao0nt+g7nsFmgFE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E764BD81FF118A22C1D078B450FAFF5036EA11D0FE98A622175942B7DA775E097372FA
sha3_384: 6dbca933be9f1405051df958a6ba094c8ca89f8f3aff6797dcdeb999eeb37cd7bc275c1a568dd00a6acb09a1e62757e6
ep_bytes: e8f82a0000e978feffff8bff558bec81
timestamp: 2010-10-22 09:12:17

Version Info:

0: [No Data]

VirTool:Win32/Obfuscator.NZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.m9gf
DrWebTrojan.Packed.21888
MicroWorld-eScanGen:Variant.Dropper.41
ClamAVWin.Trojan.Agent-314032
FireEyeGeneric.mg.c94cf67f2977e861
SkyhighGenericR-HJI!C94CF67F2977
McAfeeGenericR-HJI!C94CF67F2977
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Agent.Win32.119962
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaVirTool:Win32/Obfuscator.badef865
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.36680.tuZ@aKmalEgi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.Agent.PAY.Gen
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Dropper.41
NANO-AntivirusTrojan.Win32.MLW.eecxp
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10b10a3b
EmsisoftGen:Variant.Dropper.41 (B)
F-SecureTrojan:W32/Agent.DQGR
BaiduWin32.Trojan-Dropper.Generic.h
VIPREGen:Variant.Dropper.41
SophosMal/Agent-AAM
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE1.KFDI4A
JiangminTrojan/Generic.bswt
WebrootW32.Dropper.Agent
GoogleDetected
AviraTR/Drop.Haed.A
Antiy-AVLTrojan[Dropper]/Win32.Haed
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.TrojanDropper.Haed.A@3oqw6l
ArcabitTrojan.Dropper.41
ViRobotDropper.Haed.Gen.A
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/Obfuscator.NZ
VaristW32/Dropper.AG.gen!Eldorado
AhnLab-V3Trojan/Win32.Agent.R5847
VBA32Trojan.Packed
ALYacGen:Variant.Dropper.41
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/CI.A
RisingDropper.Win32.Undef.cah (CLASSIC)
YandexTrojan.GenAsa!GU0jLrgpNEI
IkarusTrojan-Downloader.Win32.Frethog
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Agent.PAY!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.766667
DeepInstinctMALICIOUS

How to remove VirTool:Win32/Obfuscator.NZ?

VirTool:Win32/Obfuscator.NZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment