Malware

What is “VirTool:Win32/Obfuscator.QC”?

Malware Removal

The VirTool:Win32/Obfuscator.QC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.QC virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine VirTool:Win32/Obfuscator.QC?


File Info:

name: E00028397840132DDC6F.mlw
path: /opt/CAPEv2/storage/binaries/9de3886fab5bfdfb3661a3126c5913136f7119fbad307e01c78b12a093e32261
crc32: AF4D0A91
md5: e00028397840132ddc6f57356309b6b4
sha1: cd209b05d2bc2fc4472b756fe1e02744a24312c0
sha256: 9de3886fab5bfdfb3661a3126c5913136f7119fbad307e01c78b12a093e32261
sha512: f7764c7f14124aaced3028ff596fd58c04d447987d821e574a91cc99faff907eed903e8bfa682fa24d17bb3d826e0b393329942f0e145369baddd4e88b5414ad
ssdeep: 768:nNImOXuD0t5lo+1Cj+ynyzAJAMg1iSHXK3ewi9oXS:nOJXuQ5u+gj+9adg1iS3K3so
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D803BF02A9F29BFFC5FEA23462D8311EF9A3CE55D5D3D0538E962203A4F63525224E16
sha3_384: 33b5a67fefcf27f4ba14bac578dc2b9db7a194bbba4479af8370d0e3692571a7fddb059eefcf91d7cb55253f3f336137
ep_bytes: 558bec5151515068a4160000e8d50800
timestamp: 2008-03-04 08:21:19

Version Info:

0: [No Data]

VirTool:Win32/Obfuscator.QC also known as:

LionicVirus.Win32.Generic.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Renos.37
FireEyeGeneric.mg.e00028397840132d
SkyhighArtemis!Trojan
McAfeeArtemis!E00028397840
Cylanceunsafe
VIPREGen:Variant.Renos.37
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Obfuscator.0a27f713
K7GWVirus ( 0034f5741 )
K7AntiVirusVirus ( 0034f5741 )
ArcabitTrojan.Renos.37
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Rootkit.Kryptik.DH
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Renos.37
NANO-AntivirusTrojan.Win32.Kryptik.lwtfj
AvastWin32:Alureon-ADI [Rtk]
TencentWin32.Trojan.Generic.Snkl
SophosMal/EncPk-ABF
F-SecureTrojan.TR/Rootkit.Gen5
EmsisoftGen:Variant.Renos.37 (B)
IkarusTrojan.Crypt
GoogleDetected
AviraTR/Rootkit.Gen5
Antiy-AVLVirus/Win32.AGeneric
KingsoftWin32.Virus.Generic.a
XcitiumMalware@#9kjfjf278mrv
MicrosoftVirTool:Win32/Obfuscator.QC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Renos.37
VaristW32/FakeAlert.RL.gen!Eldorado
MAXmalware (ai score=100)
PandaTrj/CI.A
RisingRootkit.Kryptik!8.452 (TFE:1:g1OKq2bMqsP)
YandexRootkit.Kryptik!lIFULwUTcMU
FortinetW32/Rorpian.C!tr
AVGWin32:Alureon-ADI [Rtk]
DeepInstinctMALICIOUS

How to remove VirTool:Win32/Obfuscator.QC?

VirTool:Win32/Obfuscator.QC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment