Spy

Spyware.CryptBot.VMP.Generic information

Malware Removal

The Spyware.CryptBot.VMP.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.CryptBot.VMP.Generic virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • CAPE detected the CryptBot malware family
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests cookies for information gathering

How to determine Spyware.CryptBot.VMP.Generic?


File Info:

name: 09C33C9229581A786A48.mlw
path: /opt/CAPEv2/storage/binaries/11e1891a940dc4222ae7c0b3e8b1308108ba62e58d14386daef8eeb38ce1cff7
crc32: B6A56A47
md5: 09c33c9229581a786a482e44eb562c9a
sha1: 810c1aa98425b6ce34f1cbc03b6db3dd6c6d9568
sha256: 11e1891a940dc4222ae7c0b3e8b1308108ba62e58d14386daef8eeb38ce1cff7
sha512: 68022dfbd8f20ac5269442c703a105dab9cab1cb3272486a03b659b6a776b643bd6c5322dee0278b10d9b125fc10e85f9cadfbf0c575c948b56591ede08f5045
ssdeep: 49152:3+iRoIIrRbic5ShvO+7JuEaZP9KvDcWK7fVvxCkKibAc3HZ2XypHZ2:3lSIIlb/gRhaZ1KLYhvxCkvbAMHZ2X0U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA850213F9A24073C82A043065579B325EBABE32193A65D313C51D9F2B364919F3F9EB
sha3_384: 060e3a7c9de915c47cbcd66ed8715262e36522998515acd8baddf66f202ff41e19220922cf0afd2c1c15abc141429719
ep_bytes: e8ddb2ffff8964241c8d6424300f840b
timestamp: 2020-06-19 06:11:56

Version Info:

0: [No Data]

Spyware.CryptBot.VMP.Generic also known as:

LionicTrojan.Win32.Coins.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.28777
MicroWorld-eScanTrojan.GenericKD.35465513
FireEyeGeneric.mg.09c33c9229581a78
McAfeeArtemis!09C33C922958
CylanceUnsafe
K7AntiVirusSpyware ( 0055134d1 )
AlibabaTrojanPSW:Win32/Coins.8fef6eed
K7GWSpyware ( 0055134d1 )
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderThetaGen:NN.ZexaF.34062.YzW@a8uVMfei
CyrenW32/S-de5df246!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.PRG
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Coins.vho
BitDefenderTrojan.GenericKD.35465513
NANO-AntivirusTrojan.Win32.Stealer.hluwrv
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan-qqpass.Qqrob.Hyx
Ad-AwareTrojan.GenericKD.35465513
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06CC0GIG21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.35465513 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.35465513
JiangminTrojan.PSW.Coins.gsw
AviraHEUR/AGEN.1138176
Antiy-AVLTrojan/Generic.ASMalwS.309E028
ArcabitTrojan.Generic.D21D2929
MicrosoftTrojan:Win32/Ymacco.AA11
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.R340705
VBA32BScope.Trojan.Wacatac
ALYacTrojan.GenericKD.35465513
MAXmalware (ai score=86)
MalwarebytesSpyware.CryptBot.VMP.Generic
TrendMicro-HouseCallTROJ_GEN.R06CC0GIG21
RisingTrojan.Generic@ML.100 (RDML:Lo9252C9eWvXTlAxmmyOJw)
YandexTrojanSpy.Agent!MHhplofgwWA
IkarusTrojan-Spy.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.PRG!tr
WebrootW32.Malware.Gen
AVGWin32:TrojanX-gen [Trj]
PandaTrj/CI.A

How to remove Spyware.CryptBot.VMP.Generic?

Spyware.CryptBot.VMP.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment