Malware

What is “VirTool:Win32/Obfuscator.UI”?

Malware Removal

The VirTool:Win32/Obfuscator.UI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.UI virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine VirTool:Win32/Obfuscator.UI?


File Info:

crc32: 4B65259A
md5: 3985b00f9fcdffd827646b62aed00df0
name: 3985B00F9FCDFFD827646B62AED00DF0.mlw
sha1: cb655cf52395690d1fe6e5ceee097e71a2261933
sha256: 8f0c98b6f37a8fee88cf822c95f1b248ba47c7c75445e7ceeb10c47a72f19415
sha512: 45b03ca4339330916afdb9f1422edede576409fcaedb4f363533119a585c66b72fd917f0a894c20a213d8d95887d3c2325709223517eef3e686c8d0aa8a7e4d1
ssdeep: 3072:FyT35i1sAabOUtxDB8DUYFmTcNLiJsCCZMBjKJyuDrtt/zsHZ5JOZxScfk:F+ssAabOUt8gYITcS4OBjKw47zC5QZZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/Obfuscator.UI also known as:

K7AntiVirusTrojan ( 0032e4f91 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.540
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.2500
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.33839
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaVirTool:Win32/Obfuscator.4203dadc
K7GWTrojan ( 0032e4f91 )
Cybereasonmalicious.f9fcdf
CyrenW32/S-e700dbfc!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.XFR
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Zbot-19936
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.2500
NANO-AntivirusTrojan.Win32.Panda.ctiqta
ViRobotTrojan.Win32.A.Zbot.217088.K
MicroWorld-eScanGen:Variant.Barys.2500
TencentWin32.Trojan-Spy.Zbot.vuj
Ad-AwareGen:Variant.Barys.2500
SophosML/PE-A + Mal/Zbot-DD
ComodoMalware@#3c3d625da03im
BitDefenderThetaGen:NN.ZexaF.34266.nmW@aiUeUVg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.3985b00f9fcdffd8
EmsisoftGen:Variant.Barys.2500 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.zlv
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.204E2C
MicrosoftVirTool:Win32/Obfuscator.UI
SUPERAntiSpywareTrojan.Agent/Gen-Obfuscator
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.2500
AhnLab-V3Spyware/Win32.Zbot.C150311
Acronissuspicious
McAfeeArtemis!3985B00F9FCD
MAXmalware (ai score=99)
VBA32Trojan.Zbot
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.83 (RDML:jojvH73bSOUvjDMqxfBX6g)
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.UWX!tr
AVGWin32:Trojan-gen

How to remove VirTool:Win32/Obfuscator.UI?

VirTool:Win32/Obfuscator.UI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment