Malware

VirTool:Win32/VBInject.ACH!bit malicious file

Malware Removal

The VirTool:Win32/VBInject.ACH!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.ACH!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine VirTool:Win32/VBInject.ACH!bit?


File Info:

crc32: B87BD57C
md5: a20cee41b2437fbb614888d24971f29d
name: A20CEE41B2437FBB614888D24971F29D.mlw
sha1: f0d27e2c8210a26da298bfce056338f716e698e3
sha256: 28773d9e5dc1ef0fb9e3c09c5d1bd3f894270336387ef74866d3634d942b19d6
sha512: df7f809a1a4081f12f066bb95777f6ca3cbd879389e906a6ee37e813aa089f60d7f31e308f73d256d819b3c3140966abc40373db87276c4e797c520db6ab6d60
ssdeep: 12288:aQ+3bG4kzZO4OhTx3JMXhWd3KcYrqiYwt7etMwWGwPbp+ODD72QLlAUeZ:U3bG4kg4OhTx32XhwYrqi2pfiDGslHe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: tendry
FileVersion: 6.07.0001
CompanyName: Zeruah6
Comments: PARONOMASIA
ProductName: Tora
ProductVersion: 6.07.0001
OriginalFilename: tendry.exe

VirTool:Win32/VBInject.ACH!bit also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0054886d1 )
LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.hn0@euu1h3ei
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirTool:Win32/VBInject.0aa1e152
K7GWTrojan ( 0054886d1 )
Cybereasonmalicious.1b2437
CyrenW32/VBKrypt.ZO.gen!Eldorado
SymantecPacked.Generic.535
ESET-NOD32a variant of Win32/Injector.EDVO
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Androm.usfk
BitDefenderGen:Heur.PonyStealer.hn0@euu1h3ei
MicroWorld-eScanGen:Heur.PonyStealer.hn0@euu1h3ei
Ad-AwareGen:Heur.PonyStealer.hn0@euu1h3ei
SophosML/PE-A + Mal/FareitVB-V
BitDefenderThetaGen:NN.ZevbaF.34058.hn0@auu1h3ei
TrendMicroTrojanSpy.Win32.LOKI.SMAL04.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.th
FireEyeGeneric.mg.a20cee41b2437fbb
EmsisoftGen:Heur.PonyStealer.hn0@euu1h3ei (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1125080
MicrosoftVirTool:Win32/VBInject.ACH!bit
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
ZoneAlarmBackdoor.Win32.Androm.usfk
GDataGen:Heur.PonyStealer.hn0@euu1h3ei
AhnLab-V3Win-Trojan/VBKrand.Gen
McAfeeFareit-FNV!A20CEE41B243
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.VB
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAL04.hp
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!Zun3QDPdz6M
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKryptik.DEBF!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASaAA

How to remove VirTool:Win32/VBInject.ACH!bit?

VirTool:Win32/VBInject.ACH!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment