Malware

VirTool:Win32/Vtub.S (file analysis)

Malware Removal

The VirTool:Win32/Vtub.S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Vtub.S virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine VirTool:Win32/Vtub.S?


File Info:

name: F6B549E688DC7AC2EE66.mlw
path: /opt/CAPEv2/storage/binaries/b838ae42ef7b25c958beeda51065213c0a4d65a2f08618d31c74145a3afc5bd2
crc32: D44B47BE
md5: f6b549e688dc7ac2ee66069376638d64
sha1: 1e883b57096d7c2cb9bf32e42ab39a30f5375e20
sha256: b838ae42ef7b25c958beeda51065213c0a4d65a2f08618d31c74145a3afc5bd2
sha512: ac7994c6168b1feb61457f722cf697adc852f271131578950fd1ec7eb7ce8e01dbbeae727146282b381a628de59265f83d2b8e24fde72cd496a9db53e11ce91a
ssdeep: 384:/TsGI/q6f7VzjuOWwxkskxiUPflBIrCmm3GCqSdkuOCkgMfVUd9MrJHWrWxur:/kqK7V/u6xkskxdPflBIrl1UzMfewrrK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110D28D46B31AC489C4018774CAAFEABC6737BC250C7485977ED07F3EACF2590791AA52
sha3_384: f5a69f566afb905535497f89293f9c7534d6fc2e4402445a640dce4bc70c84fdf9e8548cdfaa1907c9dfe9e9a7e4d3c5
ep_bytes: 60be007041008dbe00a0feff5783cdff
timestamp: 2008-04-19 17:56:18

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Microsoft Co.
ProductName: Microsoft Co
FileVersion: 1.00
ProductVersion: 1.00
InternalName: stub
OriginalFilename: stub.exe

VirTool:Win32/Vtub.S also known as:

Elasticmalicious (moderate confidence)
DrWebTrojan.MulDrop1.55505
MicroWorld-eScanGen:Variant.Johnnie.266104
FireEyeGeneric.mg.f6b549e688dc7ac2
SkyhighBehavesLike.Win32.Fake.mc
McAfeeArtemis!F6B549E688DC
Cylanceunsafe
ZillyaDropper.VB.Win32.10238
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDropper:Win32/AutoRun.59972dcf
K7GWTrojan ( 004bcce71 )
K7AntiVirusTrojan ( 004bcce71 )
BitDefenderThetaAI:Packer.620F0F5D1F
VirITTrojan.Win32.Inject.NK
SymantecW32.SillyFDC
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AXX
APEXMalicious
TrendMicro-HouseCallPAK_Otorun8
AvastWin32:Crypt-CJV [Trj]
ClamAVWin.Trojan.VB-5182
KasperskyTrojan-Dropper.Win32.VB.dnny
BitDefenderGen:Variant.Johnnie.266104
NANO-AntivirusTrojan.Win32.Agent.ecvrni
TencentMalware.Win32.Gencirc.10bf42d6
EmsisoftGen:Variant.Johnnie.266104 (B)
F-SecureMalware.BAT/Agent.52
VIPREGen:Variant.Johnnie.266104
TrendMicroPAK_Otorun8
SophosMal/FakeMS-U
IkarusTrojan.Autorun.SU
JiangminTrojan/Buzus.bjrb
WebrootW32.Trojan.Gen
GoogleDetected
AviraBAT/Agent.52
VaristW32/VBTrojan.17B!Generic
Antiy-AVLTrojan[Dropper]/Win32.VB
Kingsoftmalware.kb.b.950
MicrosoftVirTool:Win32/Vtub.S
XcitiumTrojWare.Win32.TrojanDropper.Bifrost.C@7pnv
ArcabitTrojan.Johnnie.D40F78
ViRobotTrojan.Win32.VB.68389
ZoneAlarmTrojan-Dropper.Win32.VB.dnny
GDataGen:Variant.Johnnie.266104
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C71289
VBA32Malware-Cryptor.VB.gen.1
ALYacGen:Variant.Johnnie.266104
PandaTrj/Genetic.gen
RisingWorm.Win32.Autorun.ebp (CLOUD)
YandexTrojan.DR.VB!rKWVZrhRbRY
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Autorun.SUD!tr
AVGWin32:Crypt-CJV [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/VB.AXX

How to remove VirTool:Win32/Vtub.S?

VirTool:Win32/Vtub.S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment