Malware

VirTool:Win64/Kakash!D information

Malware Removal

The VirTool:Win64/Kakash!D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win64/Kakash!D virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine VirTool:Win64/Kakash!D?


File Info:

name: EF4077D7CB0857ADA910.mlw
path: /opt/CAPEv2/storage/binaries/8a2372c6068baebf19c2725fa065faba0e6d664d32b327719a0de9ddc8624f25
crc32: CBB9B09E
md5: ef4077d7cb0857ada9106326340727d1
sha1: edd1c6aecbbe8bdaac291cf09774e70dd7f95a81
sha256: 8a2372c6068baebf19c2725fa065faba0e6d664d32b327719a0de9ddc8624f25
sha512: 1e362a578357c091cd03b435c4ae6ef3f3182ebb6d53003f073e199b880042b22a2b81d1359c573ec5d31dbbcb99a7eb85390b8031542289b87a9d6714526ac9
ssdeep: 49152:ahu2BTl2rb/TbvO90dL3BmAFd4A64nsfJaHkNb1cHwgTqmf:SuwOSmf
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T14E853A63BC9154FDC4AEC230C96AD29176317898073263C7AF51EABA1F72BD41E78364
sha3_384: 779221e79872c164ef92848678802b57d47e89e482e6d871d667f363d560034dadef5fc29ba2273c85f007f68b7092ca
ep_bytes: 4883ec28488b05b5331a00c700000000
timestamp: 2021-11-29 05:33:03

Version Info:

FileDescription: Microsoft PowerPoint
FileVersion: 16.0.14326.20404
InternalName: Powerpnt
OriginalFilename: Powerpnt.exe
ProductName: Microsoft Office
ProductVersion: 16.0.14326.20404
Translation: 0x0409 0x04b0

VirTool:Win64/Kakash!D also known as:

McAfeeArtemis!EF4077D7CB08
MalwarebytesTrojan.Meterpreter
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
APEXMalicious
McAfee-GW-EditionArtemis!Trojan
SophosATK/ScareCrow-A
AviraHEUR/AGEN.1145901
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftVirTool:Win64/Kakash.gen!D
CynetMalicious (score: 100)

How to remove VirTool:Win64/Kakash!D?

VirTool:Win64/Kakash!D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment