Malware

About “VirTool:Win32/Obfuscator.XZ” infection

Malware Removal

The VirTool:Win32/Obfuscator.XZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator.XZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine VirTool:Win32/Obfuscator.XZ?


File Info:

crc32: 8C2C326A
md5: 9d458fcd79a13b90bc458f989f43f47f
name: task1.exe.mentah
sha1: c5e1585b2f018b5252c68728b5135b505ac6a156
sha256: 863ed21ca68691dfb5131f444984c8d36faa92e09c22826621e85989d900814c
sha512: 1dd8e96909f96991b9fdc4b3876ae1510a4ed2365be5c8ee0e02b48bc58c4a07404b8ff7699c222fdef92599c2b6711af41be4696cb3b4afd900033e8108265c
ssdeep: 12288:aeNE+4Qj1cpdmbqMJX3RIlbfPiB1vAY+43ZQZNNfeX0:7E+n10MbIlbfP21vGHfeX0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/Obfuscator.XZ also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.33035527
FireEyeGeneric.mg.9d458fcd79a13b90
CylanceUnsafe
K7AntiVirusTrojan ( 004b8cfb1 )
BitDefenderTrojan.GenericKD.33035527
K7GWTrojan ( 004b8cfb1 )
Cybereasonmalicious.b2f018
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34084.AKW@aOzRMrgi
F-ProtW32/SuspPack.DX.gen!Eldorado
SymantecPacked.Vmpbad!gen4
ESET-NOD32a variant of Win32/Packed.VMProtect.AAH
TrendMicro-HouseCallTROJ_GEN.R04AC0DB620
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33035527
APEXMalicious
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazq9qOD40Nfe29O6AvAJcRsJ)
Ad-AwareTrojan.GenericKD.33035527
EmsisoftTrojan.GenericKD.33035527 (B)
ComodoVirus.Win32.Virut.CE@1fhkga
F-SecureTrojan.TR/Black.Gen2
TrendMicroTROJ_GEN.R04AC0DB620
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
SophosMal/VMProtBad-A
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
AviraTR/Black.Gen2
MAXmalware (ai score=83)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F81507
MicrosoftVirTool:Win32/Obfuscator.XZ
Acronissuspicious
ALYacTrojan.GenericKD.33035527
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove VirTool:Win32/Obfuscator.XZ?

VirTool:Win32/Obfuscator.XZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment