Malware

VirTool:Win32/Vbinder.CO removal tips

Malware Removal

The VirTool:Win32/Vbinder.CO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What VirTool:Win32/Vbinder.CO virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine VirTool:Win32/Vbinder.CO?


File Info:

crc32: 5B171128
md5: 0734394f1d28d25b9d6bb97b83c7498f
name: 23062511.jpg
sha1: 1601f9aeedd9ada184398ee8c3b223d9eed12047
sha256: 499d59b5f31e8b25d8a4fcb32ceef5efd7fc8408efa2fc34bbebfbf6ce1d2e33
sha512: e3d3b4462565285088e45e0c7cb14d2bd4fe234c6be4ac5826567f075032dbf1a567e828b784231512d079fa37ae61fb16ab5fdf9507506b1bb0c389552cbc4c
ssdeep: 24576:GR7YW+eTnCIk39UtGR1KIwGAnzeHi7YmJXFsoPvWZ:GNNGtUIXpw3nzeHE5Fso3W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/Vbinder.CO also known as:

BkavW32.GenericBinderLnr.Trojan
MicroWorld-eScanDropped:Trojan.GenericKDZ.59687
CAT-QuickHealVirTool.Vbinder.CO5
McAfeeTrojan-FDDZ!0734394F1D28
MalwarebytesHackTool.Binder
SUPERAntiSpywareTrojan.Agent/Gen-Binder
K7AntiVirusTrojan ( 004babd11 )
AlibabaHackTool:Win32/Binder.3fc39518
K7GWTrojan ( 004babd11 )
Cybereasonmalicious.f1d28d
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.32250.evW@aa@0JHiG
CyrenW32/Backdoor.FVDJ-1096
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.AGBZ
BaiduWin32.Trojan-Dropper.Binder.m
APEXMalicious
ClamAVWin.Trojan.Binder-6
KasperskyHackTool.Win32.Binder.bs
BitDefenderDropped:Trojan.GenericKDZ.59687
Paloaltogeneric.ml
Ad-AwareDropped:Trojan.GenericKDZ.59687
EmsisoftGen:Variant.Binder.1 (B)
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
F-SecureTrojan.TR/Kryptik.ybltb
DrWebTrojan.MulDrop2.39589
VIPRETrojan-Dropper.Win32.Binder.bs (v)
TrendMicroTROJ_BINDER_FC1700C9.UVPA
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.0734394f1d28d25b
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
F-ProtW32/Backdoor2.HKXU
JiangminHackTool.Binder.bh
AviraTR/Kryptik.ybltb
MAXmalware (ai score=89)
Antiy-AVLTrojan[PSW]/MSIL.Heye
MicrosoftVirTool:Win32/Vbinder.CO
Endgamemalicious (high confidence)
ViRobotTrojan.Win32.A.Swisyn.49120
ZoneAlarmHackTool.Win32.Binder.bs
GDataWin32.Trojan.Binder.A
AhnLab-V3HackTool/Win32.Vbinder.R12127
Acronissuspicious
VBA32Binder.Celesty
ALYacDropped:Trojan.GenericKDZ.59687
CylanceUnsafe
ESET-NOD32Win32/TrojanDropper.Binder.NBH
TrendMicro-HouseCallTROJ_BINDER_FC1700C9.UVPA
RisingDropper.Binder!1.AEB1 (CLASSIC)
YandexHackTool.Binder!IMtdREcP3/k
IkarusTrojan.Win32.Dorv
MaxSecureHackTool.W32.Binder.bs
FortinetW32/Dropper.NBH!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Hacktool.4af

How to remove VirTool:Win32/Vbinder.CO?

VirTool:Win32/Vbinder.CO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment