Malware

VirTool:Win32/Obfuscator!bit information

Malware Removal

The VirTool:Win32/Obfuscator!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Obfuscator!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup

Related domains:

baidu.com
coolinrek.eu
swkksblqrljvgpavqoj.eu
creunjqukjg.eu

How to determine VirTool:Win32/Obfuscator!bit?


File Info:

crc32: 0839BB8B
md5: 5180edd2ad159ed5181cabfd62da69b8
name: 5180EDD2AD159ED5181CABFD62DA69B8.mlw
sha1: 13f80d2f379e7798757c7425a342b46c78684b71
sha256: 37d9032d0cce20e1aa4c68ac45b496c98179fe817a514b114350ea1119c1b324
sha512: 92b974440efd4306bd48438f754f4e1a51bec995146f9257289433a2d4c09a19a2c22f0cad283c76a1f77040a32f8df82633acdea4a84fa52e63f98b4fca63c6
ssdeep: 12288:/GSg8vc3vGt7nZqXKRfXXGrC8tandXImwXqvGKw:+Sg8E/G1Z4mfXXGrCZImwl
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: The CDex Project - http://cdex.mu/ 2006-2014 (c)
InternalName: Burden
CompanyName: The CDex Project - http://cdex.mu/
FileDescription: Own Receive
LegalTrademarks: The CDex Project - http://cdex.mu/ 2006-2014 (c)
ProductName: Burden
ProductVersion: 3.7.6.8
PrivateBuild: 3.7.6.8
Translation: 0x0409 0x04b0

VirTool:Win32/Obfuscator!bit also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Ramnit.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.44632
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Scarab.43
CylanceUnsafe
ZillyaTrojan.Ramnit.Win32.6325
SangforTrojan.Win32.Save.a
Cybereasonmalicious.2ad159
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Ramnit.CT
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Ramnit.deg
BitDefenderGen:Variant.Ransom.Scarab.43
NANO-AntivirusTrojan.Win32.Ramnit.exusoj
MicroWorld-eScanGen:Variant.Ransom.Scarab.43
TencentWin32.Virus.Ramnit.Suds
Ad-AwareGen:Variant.Ransom.Scarab.43
SophosMal/Generic-S
ComodoMalware@#lmmml5af5hv7
BitDefenderThetaGen:NN.ZexaF.34058.ymKfaG@Vvini
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Downloader.fc
FireEyeGeneric.mg.5180edd2ad159ed5
EmsisoftGen:Variant.Ransom.Scarab.43 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1130305
eGambitUnsafe.AI_Score_87%
MicrosoftVirTool:Win32/Obfuscator!bit
ZoneAlarmTrojan.Win32.Ramnit.deg
GDataGen:Variant.Ransom.Scarab.43
AhnLab-V3Win-Trojan/Sagecrypt.Gen
McAfeeArtemis!5180EDD2AD15
MAXmalware (ai score=84)
MalwarebytesMalware.AI.4088605498
PandaTrj/CI.A
IkarusTrojan.Win32.Ramnit
AVGFileRepMalware
Qihoo-360Win32/Virus.Ramnit.HwsBEpsA

How to remove VirTool:Win32/Obfuscator!bit?

VirTool:Win32/Obfuscator!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment