Malware

VirTool:Win32/VBInject.PH!bit malicious file

Malware Removal

The VirTool:Win32/VBInject.PH!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.PH!bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
onlygoodman.com
ww5.onlygoodman.com

How to determine VirTool:Win32/VBInject.PH!bit?


File Info:

crc32: D944AA20
md5: 9e0beb806f7f82db6bebf9b113d52c95
name: 9E0BEB806F7F82DB6BEBF9B113D52C95.mlw
sha1: 4f64a48d37db4694dd529cd2410f47755148f341
sha256: 04ec494dbe31926183fa5df683da21244c6c91df6d3e3d097c59aa637ddc12d4
sha512: e9de990e50778e1e18765d86f2cd77a254ee1a8ac755aa6514a8bf7fd902a12ba3da0c399d107d6a4a2cf04c6a45722dca6faef57f106e4525acc945d4841095
ssdeep: 3072:3yf+hC4KurbnrDs/jResakHIZkkbihybsEkKPYrMNTh/+:I+bKMvA/NesHoZk8ihGsfKPYrMNTh/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Darkens
FileVersion: 4.03
CompanyName: ANTEL
ProductName: APEn AEDIa AlA
ProductVersion: 4.03
FileDescription: ARAClE AORporaTioN
OriginalFilename: Darkens.exe

VirTool:Win32/VBInject.PH!bit also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052615d1 )
LionicTrojan.Win32.VBKrypt.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.40101108
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.292942
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0052615d1 )
Cybereasonmalicious.06f7f8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DVQJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.VBKrypt.zaea
BitDefenderTrojan.GenericKD.40101108
NANO-AntivirusTrojan.Win32.VBKrypt.exrufz
MicroWorld-eScanTrojan.GenericKD.40101108
TencentWin32.Trojan.Vbkrypt.Htvv
Ad-AwareTrojan.GenericKD.40101108
SophosML/PE-A + Mal/FareitVB-M
ComodoMalware@#3eld9iaf5cb05
BitDefenderThetaGen:NN.ZevbaF.34142.Am0@aSB5kgmi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPFAREIT.SMVB
McAfee-GW-EditionFareit-FKN!9E0BEB806F7F
FireEyeGeneric.mg.9e0beb806f7f82db
EmsisoftTrojan.GenericKD.40101108 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.VB.pxixo
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.245B5D8
MicrosoftVirTool:Win32/VBInject.PH!bit
GridinsoftTrojan.Win32.Gen.vb!n
GDataTrojan.GenericKD.40101108
AhnLab-V3Trojan/Win32.VBKrypt.R219638
McAfeeFareit-FKN!9E0BEB806F7F
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_HPFAREIT.SMVB
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.VBKrypt!wOaGXTVQSTM
IkarusTrojan-Dropper.Win32.Dorifel
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DWNS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove VirTool:Win32/VBInject.PH!bit?

VirTool:Win32/VBInject.PH!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment