Malware

Should I remove “Heur.VB.Krypt.11 (B)”?

Malware Removal

The Heur.VB.Krypt.11 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.VB.Krypt.11 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Heur.VB.Krypt.11 (B)?


File Info:

crc32: 0FDC696E
md5: cba022303a657ef40256dc61d56adafa
name: upload_file
sha1: c461314a020476e69b3621ef3cc1f3ff0b4cbed0
sha256: 9bdecf70f8ecde2d83fb7e7bf513abe5db6531fdc4f773a47e22f6a2f8509d16
sha512: 392b248abac35e929543c8f9d828a94c02128548cfd766158bf8a53da549700cd61b77cdb387a46c81c67cfb7cc6eaf4188974a50e4ad77f3b27d29db1e0bd53
ssdeep: 1536:iqGoZK88dxdeVKEMPSybW0Gr7J11IbuKkGoh:iqGoZKRLd6KxwhJ0KKkGoh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: xa9Thunderbird and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable.
InternalName: thunderbird
FileVersion: 68.12
CompanyName: Mozilla Corporation
LegalTrademarks: Thunderbird is a Trademark of The Mozilla Foundation.
Comments: Mozilla Thunderbird Mail and News Client
ProductName: Thunderbird
ProductVersion: 68.12
FileDescription: Thunderbird
OriginalFilename: thunderbird.exe

Heur.VB.Krypt.11 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.VB.Krypt.11
FireEyeGeneric.mg.cba022303a657ef4
Qihoo-360Generic/Trojan.eae
McAfeeRDN/Generic.grp
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 00570e281 )
BitDefenderGen:Heur.VB.Krypt.11
K7GWTrojan ( 00570e281 )
Cybereasonmalicious.03a657
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H09JC20
KasperskyTrojan.Win32.Vebzenpak.aazx
AlibabaTrojan:Win32/Vebzenpak.d13e842b
Ad-AwareGen:Heur.VB.Krypt.11
F-SecureHeuristic.HEUR/AGEN.1119968
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Trojan.qm
SentinelOneDFI – Suspicious PE
EmsisoftGen:Heur.VB.Krypt.11 (B)
APEXMalicious
AviraHEUR/AGEN.1119968
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.VB.Krypt.11
ZoneAlarmTrojan.Win32.Vebzenpak.aazx
GDataGen:Heur.VB.Krypt.11
CynetMalicious (score: 100)
ALYacGen:Heur.VB.Krypt.11
MAXmalware (ai score=81)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EUAU
RisingMalware.Undefined!8.C (TFE:5:RloPtKZ5sWF)
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_95%
FortinetW32/GenKryptik.EUAU!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Heur.VB.Krypt.11 (B)?

Heur.VB.Krypt.11 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment