Malware

VirTool:Win32/Vbinder!pz removal tips

Malware Removal

The VirTool:Win32/Vbinder!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Vbinder!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine VirTool:Win32/Vbinder!pz?


File Info:

name: 65EF9BF8A9A2C47535CA.mlw
path: /opt/CAPEv2/storage/binaries/fc29f0f58da254383ec075526dbb5607f4ef31704ee20266509c13b24ee0d200
crc32: 8925796D
md5: 65ef9bf8a9a2c47535cacdfda613dcaa
sha1: bb8b31fdec00475f004b2b05101b1a1ce02decf9
sha256: fc29f0f58da254383ec075526dbb5607f4ef31704ee20266509c13b24ee0d200
sha512: 9287132307db4c7c7411aeb8ec8d18d2c7f5c9b85f924adc080cbeb6c63fcc1e62f580cb15d328db5f87d3e39205e441fccc0c704a4b8d04a6ae8f7117e37780
ssdeep: 6144:ePUDYWZrQ+ONFDTIvgte8R2rHFllXgDMWd65QXoHqxVDTG/r1pAa+/mf2X+AxiG:ePU8WZrQ+ONFDTIvgte8R2rHFllXgDME
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15624C63DA260A73EE416D6F9286E8398046E6D3A25C4E447FBC27B1972F19F3D121353
sha3_384: 41ea33600ffb37f7eb789018b79983f581fb0defd086b788b165e00c022e53e15c00bf357ef735ce1759b60a7a064954
ep_bytes: 684c3e4000e8eeffffff000048000000
timestamp: 1997-05-31 07:36:39

Version Info:

Translation: 0x0409 0x04b0
ProductName: ukuYzzew
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ciitDgUobm
OriginalFilename: ciitDgUobm.exe

VirTool:Win32/Vbinder!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Chinky.7
FireEyeGeneric.mg.65ef9bf8a9a2c475
CAT-QuickHealW32.Virut.Cur1
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.cu
Cylanceunsafe
VIPREGen:Variant.Chinky.7
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.dec004
ArcabitTrojan.Chinky.7
BaiduWin32.Virus.Virut.gen
VirITWin32.Scribble.AC
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/Virut.NBP
APEXMalicious
ClamAVWin.Trojan.Vobfus-44
KasperskyWorm.Win32.Vobfus.dflz
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.VBKrypt.cihufz
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:Vitro [Inf]
RisingWorm.AutoRun!1.E3A6 (CLASSIC)
SophosMal/KoobHeur-A
F-SecureTrojan.TR/VB.Krypt.jahmb
DrWebTrojan.VbCrypt.81
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Chinky.7 (B)
IkarusTrojan.Win32.Otran
GoogleDetected
AviraTR/VB.Krypt.jahmb
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumVirus.Win32.Virut.CE@5jedjj
MicrosoftVirTool:Win32/Vbinder!pz
ViRobotTrojan.Win32.A.VBKrypt.212992.BW
ZoneAlarmWorm.Win32.Vobfus.dflz
GDataGen:Variant.Chinky.7
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36744.nm1@aKR7XEni
ALYacGen:Variant.Chinky.7
MAXmalware (ai score=88)
VBA32BScope.Malware-Cryptor.VBCR.7212
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!a4XzcrC+ar4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.AZGU!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove VirTool:Win32/Vbinder!pz?

VirTool:Win32/Vbinder!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment