Trojan

About “Trojan.Crypt.VB” infection

Malware Removal

The Trojan.Crypt.VB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.VB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Installs a browser addon or extension
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Detects Bochs through the presence of a registry key
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Crypt.VB?


File Info:

name: 246328D9ACC972A84E22.mlw
path: /opt/CAPEv2/storage/binaries/038b744ec90dda9b7bc7f459017881b31d3bdce0a5de160a0c4d4eec1c1e03db
crc32: 2ABD29F6
md5: 246328d9acc972a84e22863ec4c79e0a
sha1: 7cdcc4b461b789968e15eec97cb6c82c53b091de
sha256: 038b744ec90dda9b7bc7f459017881b31d3bdce0a5de160a0c4d4eec1c1e03db
sha512: 45742d96aae99aec14c7c9a0fb086c6bd37eb5bcf3c0ed4f339b55b0abd3e2d891c729da4ab8fb3f1f2690de1234a1af7768f8e7280a31bf9e4799fd7861d0b6
ssdeep: 768:+iZNPp0b5BbrMVUTBv6mkZ8jA7IwnDoSdJ:+WNBGBrM6Fv6mkqyoc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A132949F616C1ACCA38C07BE560C1725F282EBA94B7C77B35663E672EB83411916D32
sha3_384: c0beb9e4468904e462ba1f4c9137dc73163fb2253000eed536aa30d8da754ce7b9eabf91ea6d3adce1f15d4e3dba1c26
ep_bytes: 60be003041008dbe00e0feff5783cdff
timestamp: 2006-03-21 06:48:17

Version Info:

0: [No Data]

Trojan.Crypt.VB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.Heur.cmGfrrhXxLpab
FireEyeGeneric.mg.246328d9acc972a8
SkyhighBehavesLike.Win32.Generic.pm
McAfeeGeneric VB.do
MalwarebytesTrojan.Crypt.VB
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
SymantecW32.Rontokbro@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.AN
APEXMalicious
TrendMicro-HouseCallWORM_BRONTOK.BX
ClamAVLegacy.Trojan.Agent-1388589
KasperskyVirus.Win32.VB.an
BitDefenderGen:Trojan.Heur.cmGfrrhXxLpab
NANO-AntivirusTrojan.Win32.VB.bmgfxp
AvastWin32:Malware-gen
TencentVirus.Win32.VB.kc
EmsisoftGen:Trojan.Heur.cmGfrrhXxLpab (B)
GoogleDetected
F-SecureTrojan.TR/Brontok.A.2
DrWebTrojan.MulDrop4.3118
VIPREGen:Trojan.Heur.cmGfrrhXxLpab
TrendMicroWORM_BRONTOK.BX
Trapminemalicious.high.ml.score
SophosMal/VB-F
IkarusVirus.Win32.VB.an
VaristW32/VBTrojan.17E!Maximus
AviraTR/Brontok.A.2
Kingsoftmalware.kb.b.940
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumWin32.VB.AN@2c1e
ArcabitTrojan.Heur.cmGfrrhXxLpab
ZoneAlarmVirus.Win32.VB.an
GDataGen:Trojan.Heur.cmGfrrhXxLpab
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Obfuscated.R55941
BitDefenderThetaAI:Packer.69C19FEE1D
ALYacGen:Trojan.Heur.cmGfrrhXxLpab
MAXmalware (ai score=86)
VBA32Virus.Win32.VB.an
Cylanceunsafe
PandaTrj/Genetic.gen
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
YandexTrojan.GenAsa!KUbF8ei+G18
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.216125040.susgen
FortinetW32/VB.AN
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan.Crypt.VB?

Trojan.Crypt.VB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment