Malware

VirTool:Win32/VBInject.BAW!bit removal tips

Malware Removal

The VirTool:Win32/VBInject.BAW!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.BAW!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/VBInject.BAW!bit?


File Info:

crc32: FEEEBEAA
md5: b5ce76d2eeed689107d0eb11702f0e42
name: balance_payment.exe
sha1: cd8c2ca413c7b1bb4af618de95403622197c29d1
sha256: 273c77645d8ebf47a80ec3a6803aeafdaec6dfe9306371ad6fdc8de67d5287f5
sha512: 1d73e5c48b57d8a61e7d197603111412f35eb1b1f12db7da6a2f00dd43882851cfb613e00c23c51c12489f57ad51a672cc1f5bff57d453dfc63d8dcb4886f768
ssdeep: 6144:YNoTXQ1QczsHlwrwFO/NwtTQKZb859q/+DjaaCu7Lw+hrgZgcJ6UYSL:YNoLMSl6ZwtEP9qWDjZo+hg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.03.0009
InternalName: dravidic
FileVersion: 1.03.0009
OriginalFilename: dravidic.exe
ProductName: processual

VirTool:Win32/VBInject.BAW!bit also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.PonyStealer.8
CAT-QuickHealTrojanpws.Heye
McAfeeFareit-FOQ!B5CE76D2EEED
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Variant.PonyStealer.8
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
Invinceaheuristic
NANO-AntivirusTrojan.Win32.Heye.fpssdg
CyrenW32/Trojan.ZBNR-1029
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R05AC0DDU19
Paloaltogeneric.ml
ClamAVWin.Dropper.Fareit-6959200-0
GDataGen:Variant.PonyStealer.8
KasperskyTrojan-PSW.Win32.Heye.gub
AlibabaTrojanPSW:Win32/Heye.15031bcb
AvastWin32:Malware-gen
TencentWin32.Trojan-qqpass.Qqrob.Pgws
Endgamemalicious (high confidence)
SophosMal/FareitVB-N
F-SecureHeuristic.HEUR/AGEN.1022806
TrendMicroTROJ_GEN.R05AC0DDU19
McAfee-GW-EditionBehavesLike.Win32.Fareit.jc
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Diple!O
EmsisoftGen:Variant.PonyStealer.8 (B)
IkarusTrojan.VB.Crypt
JiangminTrojan.PSW.Heye.abd
WebrootW32.Injector.Gen
AviraHEUR/AGEN.1022806
Antiy-AVLTrojan[PSW]/Win32.Heye
ArcabitTrojan.PonyStealer.8
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmTrojan-PSW.Win32.Heye.gub
MicrosoftVirTool:Win32/VBInject.BAW!bit
AhnLab-V3Trojan/Win32.VBMalpack.R268718
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Variant.PonyStealer.8
MAXmalware (ai score=94)
Ad-AwareGen:Variant.PonyStealer.8
ESET-NOD32a variant of Win32/Injector.EFDZ
RisingTrojan.Fuery!8.EAFB (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_89%
FortinetW32/Injector.EFDZ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.2eeed6
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.PSW.878

How to remove VirTool:Win32/VBInject.BAW!bit?

VirTool:Win32/VBInject.BAW!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment