Malware

VirTool:Win32/Obfuscator.S removal tips

Malware Removal

The VirTool:Win32/Obfuscator.S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.S virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VirTool:Win32/Obfuscator.S?


File Info:

name: CDEB3B96B4F4FE02BC61.mlw
path: /opt/CAPEv2/storage/binaries/4da11090ec9ad009ff4649ff5893dd7921c4015ec044417126febe18b96abeb9
crc32: 22B27033
md5: cdeb3b96b4f4fe02bc61a3b067e5a19a
sha1: 9cc3411cf20062408f9a5bacfc6879ce5a6ec5f5
sha256: 4da11090ec9ad009ff4649ff5893dd7921c4015ec044417126febe18b96abeb9
sha512: 48d84a895a13a5cc8b5cb38c3c51912fd991d9f071b261c3dfe6580f4452ce4957c34c97ed6198cf6439577616419ff377038409fbf01007b9449c712f5ee7bd
ssdeep: 1536:/2189JsQ6ZsM01g5iSwRJWEyq4DSruYtM4sOgCRloJR/0Jo7lYsY1L:/FD9e1inWE/4D+XllZJwlYL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145735E33798A8CB6E693013005946724BBFEBD34252DDC979B0809C5EC65BCFB67D24A
sha3_384: 06b6edfb140531887005a195c250e771ce7943d263a1a556c479a6f4f0422532662b47c995bfe4a0004b7bc5877be3d6
ep_bytes: 6033c08d480d50e2fd8bec648b403078
timestamp: 2007-12-17 16:42:54

Version Info:

0: [No Data]

VirTool:Win32/Obfuscator.S also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.DNSChanger.BX
ClamAVWin.Trojan.DNSChanger-167
McAfeeDNSChanger.ee.gen
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00021afd1 )
K7GWTrojan ( 00021afd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36250.eiW@aya1r2o
CyrenW32/Trojan2.AEBC
SymantecTrojan.Packed.7
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.BOA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.DNSChanger.aum
BitDefenderTrojan.DNSChanger.BX
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
SUPERAntiSpywareTrojan.Unclassified/K-Series-A
AvastWin32:DNSChanger-SK [Trj]
EmsisoftTrojan.DNSChanger.BX (B)
F-SecureBackdoor.BDS/Backdoor.Gen
VIPRETrojan.DNSChanger.BX
TrendMicroTROJ_DNSCHANG.AM
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.cdeb3b96b4f4fe02
SophosMal/Behav-010
SentinelOneStatic AI – Malicious PE
GDataTrojan.DNSChanger.BX
JiangminTrojan/DNSChanger.fww
AviraBDS/Backdoor.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.DNSChanger
XcitiumTrojWare.Win32.DNSChanger.AUM@l9a32
ArcabitTrojan.DNSChanger.BX
ZoneAlarmTrojan.Win32.DNSChanger.aum
MicrosoftVirTool:Win32/Obfuscator.S
GoogleDetected
AhnLab-V3Win-Trojan/Dnschanger.90267
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.DNSChanger.BX
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_DNSCHANG.AM
RisingTrojan.Zlob!1.A07E (CLASSIC)
YandexPacked/ZCrypt
IkarusTrojan.DNSChanger
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.AAC!tr
AVGWin32:DNSChanger-SK [Trj]
Cybereasonmalicious.6b4f4f
DeepInstinctMALICIOUS

How to remove VirTool:Win32/Obfuscator.S?

VirTool:Win32/Obfuscator.S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment