Malware

Should I remove “VirTool:Win32/VBInject.AJA!bit”?

Malware Removal

The VirTool:Win32/VBInject.AJA!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.AJA!bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
top.eaglee1.xyz

How to determine VirTool:Win32/VBInject.AJA!bit?


File Info:

crc32: 2E969563
md5: a0abf6f3d37b89d95d28f8b8dab955e6
name: xy.exe
sha1: e70d71f9fd000fde5cbf030d75c4c8eae96cadbf
sha256: 76dda78693e017f2115b698b091a35c98a7c886144da10ec67468ffa9b0fa1f8
sha512: bc781c56db8ad51904b2f2129c1070668611dc8de315c82298616021cb2d860d73d842b06b6f9a3e1d4633ff195acc24d05591bc24cfa5db9893226a5bb70c50
ssdeep: 6144:9qiYLcjvnMHhYVPzbRerkjXU1mjqiGidFv16+HsbVsK2aIUo1ETyaIUob4:9S4vnMHON1ercU8eiGidFv1jHsbVsk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: WinWord
FileVersion: 15.00.4420
CompanyName: Microsoft Corporation
ProductName: Microsoft Office 2013
ProductVersion: 15.00.4420
FileDescription: Microsoft Word
OriginalFilename: WinWord.exe

VirTool:Win32/VBInject.AJA!bit also known as:

MicroWorld-eScanGen:Heur.PonyStealer.Mm1@dK07wWpi
FireEyeGeneric.mg.a0abf6f3d37b89d9
McAfeeFareit-FLU!A0ABF6F3D37B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00537f651 )
BitDefenderGen:Heur.PonyStealer.Mm1@dK07wWpi
K7GWTrojan ( 00537f651 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
F-ProtW32/VBKrypt.DN.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Fareit-6626679-0
GDataGen:Heur.PonyStealer.Mm1@dK07wWpi
KasperskyTrojan.Win32.NetWire.ib
AlibabaTrojan:Win32/NetWire.9c0a3563
NANO-AntivirusTrojan.Win32.NetWire.ffpylp
AegisLabTrojan.Win32.NetWire.4!c
TencentWin32.Trojan.Falsesign.Llhb
Ad-AwareGen:Heur.PonyStealer.Mm1@dK07wWpi
EmsisoftGen:Heur.PonyStealer.Mm1@dK07wWpi (B)
ComodoMalware@#2th6dg9xeegkt
F-SecureHeuristic.HEUR/AGEN.1033395
DrWebBackDoor.Siggen2.2488
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
McAfee-GW-EditionFareit-FLU!A0ABF6F3D37B
Trapminemalicious.high.ml.score
SophosMal/FareitVB-N
IkarusTrojan.Win32.Injector
CyrenW32/VBKrypt.DN.gen!Eldorado
AviraHEUR/AGEN.1033395
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.NetWire
Endgamemalicious (high confidence)
ArcabitTrojan.PonyStealer.EAC14E
ZoneAlarmTrojan.Win32.NetWire.ib
MicrosoftVirTool:Win32/VBInject.AJA!bit
AhnLab-V3Trojan/Win32.Tiggre.C2466028
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34090.Mm1@aK07wWpi
VBA32BScope.Trojan.Azden
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DZGY
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
RisingTrojan.NetWire!8.FAFE (CLOUD)
YandexTrojan.NetWire!
SentinelOneDFI – Suspicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Injector.DZGS!tr
AVGFileRepMalware
Cybereasonmalicious.3d37b8
Qihoo-360Win32/Trojan.291

How to remove VirTool:Win32/VBInject.AJA!bit?

VirTool:Win32/VBInject.AJA!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment