Malware

VirTool:Win32/VBInject.ACT!bit (file analysis)

Malware Removal

The VirTool:Win32/VBInject.ACT!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.ACT!bit virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous binary characteristics

How to determine VirTool:Win32/VBInject.ACT!bit?


File Info:

crc32: C3FC0848
md5: bccc9298fe3e9b9176aa98eb5ffead16
name: BCCC9298FE3E9B9176AA98EB5FFEAD16.mlw
sha1: c1f2d7bb01a81f23a75e18898cf5abea0cdf2810
sha256: f93da40ea4a38d3d4c3f7f53fc7b3847bdfd93f1d11e7302c41ad2eb8e79c415
sha512: 01d534fa43e8789ebf1d89a3c8044c42447aa8c6bf1fe650a7128bb2eea575154b8483a2dbd0cf94d248a0a2531316fa17d0706e7e2fee4e759db9505e567037
ssdeep: 12288:+R2+VgL8H1PrpXa8jtdF8gK4+WqN97/PjL8J:d8ZrQ8jtdFi4yL/Pa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright xa9 2017 NVIDIA Corporation
InternalName: PackageLauncher
FileVersion: 1.00.0007
CompanyName: NVIDIA Corporation
ProductName: NVIDIA Package Launcher
ProductVersion: 1.00.0007
FileDescription: NVIDIA Package Launcher
OriginalFilename: PackageLauncher.exe

VirTool:Win32/VBInject.ACT!bit also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.rn2@di@zyroi
FireEyeGeneric.mg.bccc9298fe3e9b91
ALYacGen:Heur.PonyStealer.rn2@di@zyroi
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0051d6291 )
BitDefenderGen:Heur.PonyStealer.rn2@di@zyroi
K7GWTrojan ( 0051d6291 )
CrowdStrikewin/malicious_confidence_80% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packer.VbPack-0-6334882-0
KasperskyTrojan-Spy.Win32.Recam.ajma
NANO-AntivirusTrojan.Win32.Recam.evmbfe
AegisLabTrojan.Win32.Recam.l!c
TencentMalware.Win32.Gencirc.10ba98ba
Ad-AwareGen:Heur.PonyStealer.rn2@di@zyroi
EmsisoftGen:Heur.PonyStealer.rn2@di@zyroi (B)
F-SecureHeuristic.HEUR/AGEN.1128735
DrWebBackDoor.Wirenet.351
ZillyaTrojan.Recam.Win32.2387
TrendMicroTSPY_HPFAREIT.SM2
McAfee-GW-EditionGenericRXDJ-AY!BCCC9298FE3E
SophosML/PE-A + Mal/FareitVB-M
IkarusTrojan.Win32.Injector
JiangminTrojanSpy.Recam.cud
AviraHEUR/AGEN.1128735
eGambitPE.Heur.InvalidSig
MAXmalware (ai score=77)
Antiy-AVLTrojan[Spy]/Win32.Recam
MicrosoftVirTool:Win32/VBInject.ACT!bit
ArcabitTrojan.PonyStealer.E0AE3B
ZoneAlarmTrojan-Spy.Win32.Recam.ajma
GDataGen:Heur.PonyStealer.rn2@di@zyroi
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrand.Gen
McAfeeGenericRXDJ-AY!BCCC9298FE3E
VBA32TrojanSpy.Recam
MalwarebytesMalware.AI.4118649067
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DSOY
TrendMicro-HouseCallTSPY_HPFAREIT.SM2
RisingSpyware.Recam!8.5E5 (TFE:4:pOY4VrWQ6qK)
YandexTrojan.GenAsa!YyTYzINZj4U
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.DZZF!tr
BitDefenderThetaGen:NN.ZevbaF.34804.rn2@ai@zyroi
AVGWin32:Malware-gen
Cybereasonmalicious.8fe3e9
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Spy.4c4

How to remove VirTool:Win32/VBInject.ACT!bit?

VirTool:Win32/VBInject.ACT!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment