Malware

Should I remove “VirTool:Win32/VBInject.OR!bit”?

Malware Removal

The VirTool:Win32/VBInject.OR!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.OR!bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Greek
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

johnsmithsales.serveftp.com

How to determine VirTool:Win32/VBInject.OR!bit?


File Info:

crc32: 5B7E6007
md5: 29334f6415fba40212ff40caa672824a
name: 29334F6415FBA40212FF40CAA672824A.mlw
sha1: 1dce6dc80546154398d14737cbbbe61443c126e9
sha256: 09eb4d723286870ba29c9283df29c1cc62efe0329abf63e843bd9c372974f1ab
sha512: 7b74110812a773ad1b4f0285059ccf5a11e46ef8c2ae6d3e2abcd2333b501c92155f3f24d21d92cfbc54e8c60e6f3167f3cf6600be518f2a9faf832f75ac02cd
ssdeep: 3072:vqwTtpVTnK/EA3jY96yD8oBx21/aqGgzs9JHH1Ch84S:SSpAUj21fGgy1G
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0408 0x04b0
InternalName: Gel
FileVersion: 5.00.0005
CompanyName: ePSon
ProductName: Ikpan5
ProductVersion: 5.00.0005
OriginalFilename: Gel.exe

VirTool:Win32/VBInject.OR!bit also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.lm0@cyPx8hjG
FireEyeGeneric.mg.29334f6415fba402
ALYacGen:Heur.PonyStealer.lm0@cyPx8hjG
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00510f501 )
BitDefenderGen:Heur.PonyStealer.lm0@cyPx8hjG
K7GWTrojan ( 00510f501 )
Cybereasonmalicious.415fba
TrendMicroTSPY_HPFAREIT.SM
BitDefenderThetaGen:NN.ZevbaF.34590.lm0@ayPx8hjG
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Jaik-7580766-1
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareGen:Heur.PonyStealer.lm0@cyPx8hjG
SophosMal/FareitVB-M
F-SecureHeuristic.HEUR/AGEN.1121806
DrWebTrojan.Inject4.4871
InvinceaML/PE-A + Mal/FareitVB-M
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Heur.PonyStealer.lm0@cyPx8hjG (B)
AviraHEUR/AGEN.1121806
Antiy-AVLTrojan/Win32.Autoit
MicrosoftVirTool:Win32/VBInject.OR!bit
ArcabitTrojan.PonyStealer.EA05A4
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.PonyStealer.lm0@cyPx8hjG
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeeFareit-FHQ!29334F6415FB
MAXmalware (ai score=86)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DPOY
TrendMicro-HouseCallTSPY_HPFAREIT.SM
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.Injector!MTC4kfgrK6s
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Fareit.CVJN!tr.pws
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.3967.Malware.Gen

How to remove VirTool:Win32/VBInject.OR!bit?

VirTool:Win32/VBInject.OR!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment