Virus

Virus:Win32/Butool.A (file analysis)

Malware Removal

The Virus:Win32/Butool.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Butool.A virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Virus:Win32/Butool.A?


File Info:

name: 8A3252D7951E5115B3B7.mlw
path: /opt/CAPEv2/storage/binaries/9c7b39c3d5655d4c9fa58f88688b2526771eb1a21db2dcbb0872f9006f0d4dde
crc32: 2D2FDA3A
md5: 8a3252d7951e5115b3b7455c260f47c3
sha1: 0686d2570911df9ea540e34f577ee11e1c576c3e
sha256: 9c7b39c3d5655d4c9fa58f88688b2526771eb1a21db2dcbb0872f9006f0d4dde
sha512: 8e110f708b6750fef0dcde50906c394c34b9d341cbfab45c1de6de11ecfef1e6d6540d23ab5f4f872209087bce2273f8394fda21155ee9593f432863e4c28788
ssdeep: 24:OEhu70OaYUpJmZGsABcZk/s84D3cJ/xyZcVVFpBHHEIsGyP+1wh4jYH:OEPpJbBgk/sxDMxxyMnBH5wNhGYH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147E2529F41814D52C391293855AA1634F4BAF630FBB952226BE5E421C7633318D6AF28
sha3_384: c108d7253a4bfbc58b51040c747cb19d30bed6e67edbf5eb70c413dcba04e3e5f7c1b4d471860ffca26540d32e651f77
ep_bytes: 8b0424250000f0bf3d0000f0bf7518a1
timestamp: 2034-04-20 08:52:19

Version Info:

0: [No Data]

Virus:Win32/Butool.A also known as:

tehtrisGeneric.Malware
DrWebWin95.Whg.910
MicroWorld-eScanWin95.Butool.910.A
FireEyeGeneric.mg.8a3252d7951e5115
CAT-QuickHealW32.Butool.910
ALYacWin95.Butool.910.A
CylanceUnsafe
Cybereasonmalicious.7951e5
BitDefenderThetaAI:Packer.EFF75C041D
VirITWin95.Marburg
CyrenW32/Butool.910
Elasticmalicious (high confidence)
ESET-NOD32Win95/Butool.910
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPE_SCHOOLGIRL.A
Paloaltogeneric.ml
KasperskyVirus.Win9x.Butool.910
BitDefenderWin95.Butool.910.A
NANO-AntivirusVirus.Win32.Butool.cbzx
AvastWin95:Rainer
TencentWin32.Virus.Butool.Eana
Ad-AwareWin95.Butool.910.A
SophosW95/SchGirl-910
ComodoVirus.Win95.Butool.9100@1fd2lh
TrendMicroPE_SCHOOLGIRL.A
McAfee-GW-EditionW32/Butool.a
Trapminemalicious.high.ml.score
EmsisoftWin95.Butool.910.A (B)
SentinelOneStatic AI – Suspicious PE
GDataWin95.Butool.910.A
JiangminWin95/Butool.910
AviraW95/Butool-910
MAXmalware (ai score=80)
MicrosoftVirus:Win32/Butool.A
CynetMalicious (score: 100)
McAfeeW32/Butool.a
VBA32Trojan.Wacatac
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingWin32.HooksGirl (CLASSIC)
YandexTrojan.GenAsa!svZIbu21GNE
IkarusVirus.Win32.Poson
MaxSecureVirus.W9X.Butool.910
FortinetW32/Butool.910
AVGWin95:Rainer
PandaW32/Besc
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Virus:Win32/Butool.A?

Virus:Win32/Butool.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment