Malware

VirTool:Win32/Vtub.FH (file analysis)

Malware Removal

The VirTool:Win32/Vtub.FH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Vtub.FH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Mimics the file times of a Windows system file
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine VirTool:Win32/Vtub.FH?


File Info:

crc32: 28ECADB3
md5: c202dbbcc0480081ca83713407d7af2c
name: C202DBBCC0480081CA83713407D7AF2C.mlw
sha1: 34a9b1c240a079b65adc60ac240c5eed8ce6972b
sha256: 8c28d0d9c5402b4264ea8331c795420db63134885e460e5eaad055a53296840e
sha512: 694d0c875f41d9d72ce8af24174eaf48ad9ed92e9ec969a89d14f103d2b345c57cf5b7c9d5cf36a73ab9c66c450883f1e2c2ec2019d7bd026dae1c1707fd5b46
ssdeep: 12288:4pF3l7YPUHTGe9jU17SGmwbJGI3MWH/0+VP:4p/7YPCTGCjUJHPkVy/0+N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: Sex
FileVersion: 1.00
OriginalFilename: Sex.dll
ProductName: Sex

VirTool:Win32/Vtub.FH also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Unkbot.225
CynetMalicious (score: 100)
CMCGeneric.Win32.c202dbbcc0!MD
ALYacGen:Backdoor.Heur.Bifrose.Dm3@cGmT5Dai
CylanceUnsafe
ZillyaDropper.VB.Win32.69499
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirTool:Win32/Binder.b2fca7f8
Cybereasonmalicious.cc0480
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.VB.NMR
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Binder-9802781-0
KasperskyConstructor.Win32.Binder.w
BitDefenderGen:Backdoor.Heur.Bifrose.Dm3@cGmT5Dai
NANO-AntivirusRiskware.Win32.Binder.fpkigh
MicroWorld-eScanGen:Backdoor.Heur.Bifrose.Dm3@cGmT5Dai
TencentMalware.Win32.Gencirc.116ae0ff
Ad-AwareGen:Backdoor.Heur.Bifrose.Dm3@cGmT5Dai
SophosMal/Generic-S
ComodoTrojWare.Win32.Trojan.Generic.4429140@1us0ni
BitDefenderThetaGen:NN.ZevbaF.34608.Dm3@aGmT5Dai
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.VirRansom.gc
FireEyeGeneric.mg.c202dbbcc0480081
EmsisoftGen:Backdoor.Heur.Bifrose.Dm3@cGmT5Dai (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Dropper
MicrosoftVirTool:Win32/Vtub.FH
ArcabitGen:Backdoor.Heur.Bifrose.E9C50F
GDataGen:Backdoor.Heur.Bifrose.Dm3@cGmT5Dai
TACHYONConstructor/W32.VB-Binder.488559
McAfeeArtemis!C202DBBCC048
MAXmalware (ai score=100)
VBA32BScope.TrojanDropper.VB
PandaGeneric Malware
RisingDropper.VB!8.B2E (CLOUD)
YandexTrojan.GenAsa!ybtcid1bGZ0
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.866.susgen
FortinetW32/Binder.W!kit
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/HackTool.Binder.HykCTbIA

How to remove VirTool:Win32/Vtub.FH?

VirTool:Win32/Vtub.FH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment