Malware

About “VirTool:Win32/Obfuscator.UO” infection

Malware Removal

The VirTool:Win32/Obfuscator.UO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.UO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine VirTool:Win32/Obfuscator.UO?


File Info:

crc32: F0F50DAE
md5: 24ed5dd8e3be9181bdb58b71dbacc0a0
name: 24ED5DD8E3BE9181BDB58B71DBACC0A0.mlw
sha1: 400591b979be439b789471618cdb861aa6dc9296
sha256: 1a223ad9c2acf3773fd4f41d545fe2962d1df49cbdc0fa6649f00b96fe0205df
sha512: 106d3a83195c92da3986d4a6f854cfcc7ef61b98567749a04d48dc430e038d17de762b315a716c2dedee39dea7369d8b072424e60a3e28682727636df17808e7
ssdeep: 3072:yKn5VTTYAhx1NYnNuLwaebav2NldJNIQJDnk:yUVR1NYnocaebaeldDISDn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2000-2010 TightVNC Group
InternalName: vncviewer
FileVersion: 1.5.2.0
CompanyName: TightVNC Group
PrivateBuild:
LegalTrademarks:
Comments: Based on VNC by AT&T Research Labs Cambridge, RealVNC Ltd.
ProductName: TightVNC Win32 Viewer
SpecialBuild:
ProductVersion: 1.5.2.0
FileDescription: vncviewer
OriginalFilename: vncviewer.exe
Translation: 0x0409 0x04b0

VirTool:Win32/Obfuscator.UO also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.849045
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.923718
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.f9bc6e97
Cybereasonmalicious.8e3be9
CyrenW32/Zbot.CK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.MOB
APEXMalicious
AvastWin32:MalOb-ID [Cryp]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.849045
NANO-AntivirusTrojan.Win32.Crypted.eclarn
MicroWorld-eScanGen:Variant.Razy.849045
TencentWin32.Trojan.Kryptik.Hssz
Ad-AwareGen:Variant.Razy.849045
SophosML/PE-A + Mal/EncPk-ZC
ComodoMalware@#3vi93y676x10s
F-SecureTrojan.TR/Crypt.XPACK.Gen
BitDefenderThetaGen:NN.ZexaF.34236.Ov0@amrlXHoi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.SMYX
McAfee-GW-EditionPWS-Zbot.gen.axh
FireEyeGeneric.mg.24ed5dd8e3be9181
EmsisoftGen:Variant.Razy.849045 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.azbn
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.18B0265
MicrosoftVirTool:Win32/Obfuscator.UO
ArcabitTrojan.Razy.DCF495
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.849045
Acronissuspicious
McAfeePWS-Zbot.gen.axh
MAXmalware (ai score=99)
VBA32BScope.Trojan.Zbot.01472
PandaTrj/Banker.JJG
TrendMicro-HouseCallTSPY_ZBOT.SMYX
YandexTrojan.Kryptik!zkAlpsLLbaQ
IkarusTrojan.Win32.Extats
FortinetW32/Kryptik.HZ!tr
AVGWin32:MalOb-ID [Cryp]
Paloaltogeneric.ml

How to remove VirTool:Win32/Obfuscator.UO?

VirTool:Win32/Obfuscator.UO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment