Malware

VirTool:Win32/Obfuscator.QV!bit (file analysis)

Malware Removal

The VirTool:Win32/Obfuscator.QV!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.QV!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine VirTool:Win32/Obfuscator.QV!bit?


File Info:

crc32: BD6F262E
md5: c8c0699fe58162a87c2dc29f1dfb60ce
name: C8C0699FE58162A87C2DC29F1DFB60CE.mlw
sha1: c4ec843c6e4983e1ee5e84afb84e86b81e8f57f2
sha256: 9ad47f6ac9e174ed888bc9d4a81ac0334b0d39c898dd108fe230c5c87f092ca1
sha512: b5d750d5ccc2ff44ca7d0de334912df6eefa165c86316e0cdc5a8a297c24cb9db8e98cb622d091008d00075f959406c2a61923e43c88b408e63497886f709925
ssdeep: 3072:UCC6RW1YASGI90RDsEgOYaLbXWgLZnwhRZBVlHyhYZjE84reyNXs8WYoeGb0ZlQ:drCSSDsEgOlZnqRZBOhXid7b2KeQnbq
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

VirTool:Win32/Obfuscator.QV!bit also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0054b8501 )
LionicTrojan.Win32.GandCrypt.H!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.2080
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GandCrypt.958334e9
K7GWTrojan ( 0054b8501 )
Cybereasonmalicious.fe5816
CyrenW32/S-c52b1bf2!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GRVY
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.GandCrypt.imf
BitDefenderGen:Variant.Ransom.1646
NANO-AntivirusTrojan.Win32.GandCrypt.foyxol
MicroWorld-eScanGen:Variant.Ransom.1646
TencentWin32.Trojan.Gandcrypt.Tayi
Ad-AwareGen:Variant.Ransom.1646
SophosMal/Generic-S + Mal/Qbot-X
ComodoMalware@#zae750msc08j
F-SecureHeuristic.HEUR/AGEN.1111660
BitDefenderThetaGen:NN.ZexaF.34796.pmGfaan3HccG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.c8c0699fe58162a8
EmsisoftGen:Variant.Ransom.GandCrab.2147 (B)
JiangminTrojan.GandCrypt.zh
AviraTR/Crypt.ULPM.Gen2
eGambitUnsafe.AI_Score_69%
Antiy-AVLTrojan/Generic.ASMalwS.2B1E533
MicrosoftVirTool:Win32/Obfuscator.QV!bit
ArcabitTrojan.Ransom.GandCrab.D863
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.imf
GDataGen:Variant.Ransom.1646
AhnLab-V3Trojan/Win32.MalPe.R265570
Acronissuspicious
McAfeeArtemis!C8C0699FE581
MAXmalware (ai score=100)
VBA32BScope.Trojan.AntiAV
PandaTrj/Genetic.gen
YandexTrojan.GandCrypt!BsHmHm+Brsk
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74238594.susgen
FortinetW32/Kryptik.GRUH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwsBEpsA

How to remove VirTool:Win32/Obfuscator.QV!bit?

VirTool:Win32/Obfuscator.QV!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment