Malware

VirTool:Win32/VBInject removal guide

Malware Removal

The VirTool:Win32/VBInject is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A system process is generating network traffic likely as a result of process injection
  • Network activity contains more than one unique useragent.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

rusav1.icu

How to determine VirTool:Win32/VBInject?


File Info:

crc32: FF343BD6
md5: 17a1f7e98731df9b74b98accb650d50e
name: tt.txt
sha1: 64a96c0cfd3884f682b1b56f3e9e1b880849694f
sha256: 3ef2a739073edef534d6bbd2c426cf8e2285544d03afe33ce64526f3e5926248
sha512: 49ad8edbd470c2fd32a1317288634b6411da106510527117808b3c2eb78685c1ceb69d93eaa2047cabce5bb7da9901a00c10e071f7482d2ee5bb6af231380917
ssdeep: 6144:n6Mld0mZO7xKwkN4hzWxXAjHO4aoi8yij67LHMtBhqjeicA:ntlZQxRkN4hyxwbx0ctjbX
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9. All rights reserved. Oracle
InternalName: Crushing Driveclone's
CompanyName: Oracle
FileDescription: Passmark Sells Pictorial Csv Certcli
LegalTrademarks: Copyright xa9. All rights reserved. Oracle
Comments: Passmark Sells Pictorial Csv Certcli
ProductName: Crushing Driveclone's
Languages: English
ProductVersion: 8.4.48.4
PrivateBuild: 8.4.48.4
Translation: 0x0409 0x04b0

VirTool:Win32/VBInject also known as:

MicroWorld-eScanTrojan.GenericKD.32787857
McAfeeRDN/Generic.tfr
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.32787857
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0PL819
BitDefenderThetaGen:NN.ZexaF.33556.tmKfamW3Vdli
CyrenW32/Trojan.RGRM-4181
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.GZIC
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.32787857
KasperskyTrojan.Win32.Fsysna.fyle
NANO-AntivirusTrojan.Win32.Dwn.gkqqfz
AegisLabTrojan.Win32.Fsysna.tqXg
Endgamemalicious (moderate confidence)
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.XPACK.knbgg
DrWebTrojan.DownLoader30.50412
ZillyaTrojan.Fsysna.Win32.19052
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.17a1f7e98731df9b
EmsisoftTrojan.GenericKD.32787857 (B)
SentinelOneDFI – Suspicious PE
JiangminTrojan.Fsysna.koi
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.knbgg
Antiy-AVLTrojan/Win32.Fsysna
MicrosoftVirTool:Win32/VBInject
ArcabitTrojan.Generic.D1F44D91
AhnLab-V3Malware/Win32.Generic.C3613566
ZoneAlarmTrojan.Win32.Fsysna.fyle
Acronissuspicious
VBA32Trojan.Fsysna
ALYacTrojan.Agent.Fsysna
MAXmalware (ai score=100)
Ad-AwareTrojan.GenericKD.32787857
MalwarebytesTrojan.Renard
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PL819
YandexTrojan.Fsysna!
IkarusTrojan-Ransom.GandCrab
FortinetW32/Fsysna.EXCTUKW!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.0ad

How to remove VirTool:Win32/VBInject?

VirTool:Win32/VBInject removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment