Malware

VirTool:Win32/VBInject.OX removal tips

Malware Removal

The VirTool:Win32/VBInject.OX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.OX virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/VBInject.OX?


File Info:

crc32: 7365F0DD
md5: a4c602c9b47a5841f01fed2256c36c86
name: A4C602C9B47A5841F01FED2256C36C86.mlw
sha1: 6097240a883fd57e8eed7651bd2c1f7650e4ac33
sha256: 314f43e684e11d067b2bcf4c3896c530bf8fdb3bbdf683eef7c0d573a39ff3db
sha512: aa07e0736654ceab0848cbd0b39d23681b21ebe72a345d04f194832841806e5879db06bfd724ec8ba77669598b7cc20c161a1be9a3d02fe26b8369a217fad097
ssdeep: 3072:a7NV1IuZnVT6iqeluSE5a0PIRRKq5TJlwMWHBSnga+W0dVYKzaUmhLiNvBVIz9f:sUuX6keWI0Y1dv3oFAg/JXcr/KV55pU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: ytbrrja
FileVersion: 14.29.0005
CompanyName: MQCYBNAHT
Comments: AWTGGJCLG
ProductName: YXEPEJRMZ
ProductVersion: 14.29.0005
FileDescription: HFUQPUDID
OriginalFilename: ytbrrja.exe

VirTool:Win32/VBInject.OX also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.PornoBlocker.j!c
DrWebTrojan.Packed.21496
ALYacGen:Heur.ManBat.1
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.8456
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/PornoBlocker.31a988c7
K7GWTrojan ( 0055e4091 )
K7AntiVirusTrojan ( 0055e4091 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.ZX
APEXMalicious
AvastWin32:VB-SFD [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.PornoBlocker.jlw
BitDefenderGen:Heur.ManBat.1
NANO-AntivirusTrojan.Win32.VBInject.edfade
MicroWorld-eScanGen:Heur.ManBat.1
TencentWin32.Trojan.Pornoblocker.Lnny
Ad-AwareGen:Heur.ManBat.1
SophosML/PE-A + Mal/VBCheMan-C
ComodoTrojWare.Win32.Injector.AMXL@52ezih
BitDefenderThetaAI:Packer.36DFF17620
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.jm
FireEyeGeneric.mg.a4c602c9b47a5841
EmsisoftGen:Heur.ManBat.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PornoBlocker.al
AviraHEUR/AGEN.1117907
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.1906898
MicrosoftVirTool:Win32/VBInject.OX
ZoneAlarmTrojan-Ransom.Win32.PornoBlocker.jlw
GDataGen:Heur.ManBat.1
McAfeeArtemis!A4C602C9B47A
MAXmalware (ai score=100)
VBA32BScope.Trojan.VBKrypt
PandaGeneric Malware
IkarusTrojan-Ransom.PornoBlocker
FortinetW32/Dorkbot.BAA!tr
AVGWin32:VB-SFD [Trj]
Paloaltogeneric.ml

How to remove VirTool:Win32/VBInject.OX?

VirTool:Win32/VBInject.OX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment