Malware

VirTool:Win32/Obfuscator information

Malware Removal

The VirTool:Win32/Obfuscator is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/Obfuscator?


File Info:

crc32: F9AF1362
md5: c609f5c6af169f93c05422a470ae84c8
name: SniperE_NZA12Tr-LNG_v.1.06.exe
sha1: 1a0a6f956df5899354b09c6ee3a5747e367f7d80
sha256: a250f2268fcb256f273a5c6844b0fd255281fe53073c4872e40b351d818facb1
sha512: 8cd647222c6c97c007580fc6d87ff62d0ae22e6d2af18f8ec31ff02ce33925963b9a78fe88fb346c715ccd30db2f8d6b849e098e434b863607eeca9192a84c8a
ssdeep: 49152:03BOP8ghuAOcdGOB5JO3uiZvhlDksBGUMxZh3gcCRPa:03IP8fcH+NZPBGUMNUg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: LinGon
InternalName: SniperE_NZA+12Tr-LNG_15_July_2013_Dday
FileVersion: 1.02.0003
CompanyName: LinGon
Comments: Trainer Made By LinGon 2012 - UnMatched Quality Since 2008.
ProductName: Sniper Elite: Nazi Zombie Army - 15 July 2013 - Trainer by LinGon - v1.06
ProductVersion: 1.02.0003
FileDescription: A LinGon Trainer
OriginalFilename: SniperE_NZA+12Tr-LNG_15_July_2013_Dday.exe

VirTool:Win32/Obfuscator also known as:

BkavHW32.Packed.B608
MicroWorld-eScanTrojan.Generic.9421339
CAT-QuickHealTrojan.IGENERIC
McAfeeGeneric-FAAF!C609F5C6AF16
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
K7AntiVirusTrojan ( 00006f8a1 )
K7GWTrojan ( 00006f8a1 )
ArcabitTrojan.Generic.D8FC21B
Invinceaheuristic
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9981
NANO-AntivirusTrojan.Win32.Black.bzswsj
CyrenW32/A-7fdeb6c8!Eldorado
SymantecPacked.Vmpbad!gen4
TrendMicro-HouseCallTROJ_SPNV.03KH13
GDataTrojan.Generic.9421339
BitDefenderTrojan.Generic.9421339
SUPERAntiSpywareHack.Tool/Gen-GameHack
Ad-AwareTrojan.Generic.9421339
EmsisoftTrojan.Generic.9421339 (B)
Comodo.UnclassifiedMalware
F-SecureTrojan.Generic.9421339
DrWebTrojan.PWS.Siggen1.28916
ZillyaTrojan.Packed.Win32.35948
TrendMicroTROJ_SPNV.03KH13
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/VMProtBad-A
IkarusGen.Malware.Heur
F-ProtW32/A-7fdeb6c8!Eldorado
WebrootW32.Malware.Gen
AviraTR/Black.Gen2
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftVirTool:Win32/Obfuscator
Endgamemalicious (high confidence)
AegisLabTroj.Generic!c
ALYacTrojan.Generic.9421339
AVwareTrojan.Win32.Generic.pak!cobra
MAXmalware (ai score=100)
MalwarebytesCrackTool.Agent
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.VMProtect.AAH
YandexTrojan.Packed!ENC7HHzBIf0
SentinelOnestatic engine – malicious
AVGWin32:Trainer-F [PUP]
AvastWin32:Trainer-F [PUP]

How to remove VirTool:Win32/Obfuscator?

VirTool:Win32/Obfuscator removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment