Malware

VirTool:Win32/VBInject.OW!bit malicious file

Malware Removal

The VirTool:Win32/VBInject.OW!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.OW!bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Interacts with known DarkComet registry keys
  • Creates a slightly modified copy of itself
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
pownedfag.pw

How to determine VirTool:Win32/VBInject.OW!bit?


File Info:

crc32: 3406C1A4
md5: e7d73585f923262abea125729a0acc47
name: E7D73585F923262ABEA125729A0ACC47.mlw
sha1: 1886c3c188883a0e20826fd13e1f7592981db6ec
sha256: dd27884a47b1513a6159e462e1aeb9372b004aff501daa737851afceb35ff5d4
sha512: 7423684c0691cb8e8b81655fa0c692567b19af85f75ce506545100de55dcb835b1293ecfce0f180949696ad6bc8b5bcdb43209e364db555d247e6442e2febd82
ssdeep: 24576:DIBOJN/jscTYWWmWQxqW7wY1scEMQPkt:DnDRLWmW0wY1Nj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: icq
InternalName: Numberest1
FileVersion: 1.00.0009
LegalTrademarks:
Comments: AVAST sOFTwarE
ProductName: elecTRUM
ProductVersion: 1.00.0009
FileDescription: CAptEl Sarl
OriginalFilename: Numberest1.exe

VirTool:Win32/VBInject.OW!bit also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Tordev.976
MicroWorld-eScanGen:Heur.PonyStealer.Dn0@cSVNXtli
McAfeePacked-MI!E7D73585F923
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0050fff31 )
BitDefenderGen:Heur.PonyStealer.Dn0@cSVNXtli
K7GWTrojan ( 0050fff31 )
Cybereasonmalicious.5f9232
BitDefenderThetaGen:NN.ZevbaF.34804.Dn0@aSVNXtli
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.VBKrypt.xjbj
NANO-AntivirusTrojan.Win32.VBKrypt.eqbcph
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareGen:Heur.PonyStealer.Dn0@cSVNXtli
EmsisoftGen:Heur.PonyStealer.Dn0@cSVNXtli (B)
ComodoMalware@#1gto5kodbuacp
F-SecureHeuristic.HEUR/AGEN.1127819
ZillyaTrojan.VBKrypt.Win32.270759
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
McAfee-GW-EditionPacked-MI!E7D73585F923
FireEyeGeneric.mg.e7d73585f923262a
SophosML/PE-A + Mal/FareitVB-M
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1127819
Antiy-AVLTrojan/Win32.VBKrypt
MicrosoftVirTool:Win32/VBInject.OW!bit
ArcabitTrojan.PonyStealer.EB274B
ZoneAlarmTrojan.Win32.VBKrypt.xjbj
GDataGen:Heur.PonyStealer.Dn0@cSVNXtli
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
VBA32Trojan.VBKrypt
ALYacGen:Heur.PonyStealer.Dn0@cSVNXtli
MAXmalware (ai score=81)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DPIG
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
YandexTrojan.VBKrypt!3ySJSh3VyjI
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.DPHF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.63e

How to remove VirTool:Win32/VBInject.OW!bit?

VirTool:Win32/VBInject.OW!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment