Malware

Should I remove “VirTool:Win32/Vbinder!pz”?

Malware Removal

The VirTool:Win32/Vbinder!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Vbinder!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine VirTool:Win32/Vbinder!pz?


File Info:

name: D74F0A7485E8F0EFACEC.mlw
path: /opt/CAPEv2/storage/binaries/ecb742014c6747d3aab9a78107419e90873bf07d7dccd07d443fb148467665a2
crc32: 2378DD20
md5: d74f0a7485e8f0efacec39c6d50dbf1a
sha1: f4ea48c6a0c253a4d1f4431b165f3656ba22dcd2
sha256: ecb742014c6747d3aab9a78107419e90873bf07d7dccd07d443fb148467665a2
sha512: a80afe25d1b13f5dfcdd138d33aced7220b5dd083a222d7b57b64c6a0efbd1a454c32b8a8dd32c295c28de7b87939527ec231de9e059d7283f492ef000565aca
ssdeep: 6144:eNDd8WZrQ+ONFDTIvgte8R2rHFllXgDMWd65QXoHqxVDTG/r1pAa+/mf2X+Axi8:eNyWZrQ+ONFDTIvgte8R2rHFllXgDMWn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15924C63DA260A73AE416D6F9286E8398046E6D3A24C5E447FBC27B1972F19F3D121353
sha3_384: 56db5161ee50b042575b71b3252dbcab90e5282ad99e4dbfd5286a68ae229a15a55ef27065930d4586a5bc5c8fd0c45a
ep_bytes: 684c3e4000e8eeffffff000048000000
timestamp: 1997-05-31 07:36:39

Version Info:

Translation: 0x0409 0x04b0
ProductName: YoBwXqWo
FileVersion: 1.00
ProductVersion: 1.00
InternalName: tcestSbEJO
OriginalFilename: tcestSbEJO.exe

VirTool:Win32/Vbinder!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Chinky.7
FireEyeGeneric.mg.d74f0a7485e8f0ef
CAT-QuickHealW32.Virut.Cur1
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.cu
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.485e8f
BitDefenderThetaGen:NN.ZevbaF.36802.nm1@aKR7XEni
VirITWin32.Scribble.AC
SymantecW32.Changeup!gen15
tehtrisGeneric.Malware
ESET-NOD32Win32/Virut.NBP
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
AvastWin32:Vitro [Inf]
ClamAVWin.Trojan.Vobfus-44
KasperskyWorm.Win32.Vobfus.dflz
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.VBKrypt.cihufz
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
SophosMal/KoobHeur-A
BaiduWin32.Virus.Virut.gen
F-SecureTrojan.TR/VB.Krypt.jahmb
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Chinky.7
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Chinky.7 (B)
IkarusVirus.Win32.Vbinder
MAXmalware (ai score=86)
GoogleDetected
AviraTR/VB.Krypt.jahmb
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftVirTool:Win32/Vbinder!pz
XcitiumVirus.Win32.Virut.CE@5jedjj
ArcabitTrojan.Chinky.7
ViRobotTrojan.Win32.A.VBKrypt.212992.BW
ZoneAlarmWorm.Win32.Vobfus.dflz
GDataGen:Variant.Chinky.7
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Malware-Cryptor.VBCR.7212
ALYacGen:Variant.Chinky.7
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.AutoRun!1.E3A6 (CLASSIC)
YandexTrojan.GenAsa!a4XzcrC+ar4
SentinelOneStatic AI – Malicious PE
FortinetW32/VB.AZGU!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Vobfus.c2fc1c84

How to remove VirTool:Win32/Vbinder!pz?

VirTool:Win32/Vbinder!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment