Malware

VirTool:Win32/VBInject.ADR!bit information

Malware Removal

The VirTool:Win32/VBInject.ADR!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.ADR!bit virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Formbook malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine VirTool:Win32/VBInject.ADR!bit?


File Info:

name: C46C8A81A1B50AE74DDC.mlw
path: /opt/CAPEv2/storage/binaries/02218d687e7814e5aaa831e4222fb599164c6002b0285cf8fdfc42f89a2e8a29
crc32: DD4FE661
md5: c46c8a81a1b50ae74ddce987e43e9dba
sha1: 751bbfd2e1a6870a9253d815c160950bc5352e63
sha256: 02218d687e7814e5aaa831e4222fb599164c6002b0285cf8fdfc42f89a2e8a29
sha512: 360b38ec23122b5ae618abfbb887470a6c21a2f4729dc64329765b72b81b720d2b9cde2bc06fafde9bf8c901af103a945426e4a9632bb4d3ae7efec8d4f8134c
ssdeep: 6144:aSxZFDf+c1RIbzKmPizuUei/nq9qjrQIensveBFlFHga46fXlFfBqhktmR:1R2c1QKmPmuLigUJS/Hz3fVrq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116B4CF5D47C0A669DC3E583837CDEA2483E6BA503E694F1CBD9AF0600BB177B604C796
sha3_384: 0cf0df4714f56ddb0c58a8f91dd1b67741fdfbda14683fbb602794c85cc9d6bdffbee8d7f02de571b17d983b8b6070ae
ep_bytes: 6898134000e8eeffffff000000000000
timestamp: 1997-12-23 01:41:38

Version Info:

Translation: 0x0409 0x04b0
Comments: hyperpencil3
CompanyName: PHANEROCRYSTALLINE3
FileDescription: ahonlan
LegalCopyright: MORACEOUS
LegalTrademarks: gonocalycine0
ProductName: SWILLBOWL0
FileVersion: 1.02.0007
ProductVersion: 1.02.0007
InternalName: Bunglesome
OriginalFilename: Bunglesome.exe

VirTool:Win32/VBInject.ADR!bit also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Fareit.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Loki.25454
ClamAVWin.Trojan.Noon-7404483-0
FireEyeGeneric.mg.c46c8a81a1b50ae7
SkyhighFareit-FOQ!C46C8A81A1B5
ALYacSpyware.Infostealer.Fareit
Cylanceunsafe
ZillyaTrojan.Fareit.Win32.33498
SangforSuspicious.Win32.Save.vb
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanPSW:Win32/Fareit.85ccf14c
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36744.Fm0@a8BI3Fgi
VirITTrojan.Win32.VBZenPack_Heur
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Fareit.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Fareit.exly
BitDefenderGen:Variant.Ransom.Loki.25454
NANO-AntivirusTrojan.Win32.Fareit.fpifyd
TencentMalware.Win32.Gencirc.13ef2740
EmsisoftGen:Variant.Ransom.Loki.25454 (B)
F-SecureTrojan.TR/VBInject.igtnf
DrWebTrojan.PWS.Banker1.30619
VIPREGen:Variant.Ransom.Loki.25454
TrendMicroTrojanSpy.Win32.FAREIT.THDBCAI
SophosMal/Generic-S
IkarusTrojan.VB.Crypt
GDataGen:Variant.Ransom.Loki.25454
JiangminTrojan.PSW.Fareit.yrl
GoogleDetected
AviraTR/VBInject.igtnf
Antiy-AVLTrojan[PSW]/Win32.Fareit
Kingsoftmalware.kb.a.1000
XcitiumMalware@#3kn2yw7xb5gy1
ArcabitTrojan.Ransom.Loki.D636E
ViRobotTrojan.Win32.Z.Fareit.516096.Q
ZoneAlarmTrojan-PSW.Win32.Fareit.exly
MicrosoftVirTool:Win32/VBInject.ADR!bit
VaristW32/VBKrypt.NH.gen!Eldorado
AhnLab-V3Win-Trojan/VBKrypt.RP09.X1977
McAfeeFareit-FOQ!C46C8A81A1B5
DeepInstinctMALICIOUS
VBA32TrojanPSW.Fareit
MalwarebytesMalware.AI.3342555419
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.THDBCAI
YandexTrojan.GenAsa!pVmxxazedaA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.DLKB!tr
Cybereasonmalicious.2e1a68
PandaTrj/GdSda.A

How to remove VirTool:Win32/VBInject.ADR!bit?

VirTool:Win32/VBInject.ADR!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment