Spy Trojan

Trojan-Spy.Win32.Vkont.wkj removal instruction

Malware Removal

The Trojan-Spy.Win32.Vkont.wkj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Vkont.wkj virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Vkont.wkj?


File Info:

name: C3A438A0882CECE1069C.mlw
path: /opt/CAPEv2/storage/binaries/12a570db66717ae4f40d2d0c67367cb12012b79a20262aa5cee495185f158ee9
crc32: CDFDCA9D
md5: c3a438a0882cece1069cc923bfb527a8
sha1: 2e191c73ae9fba43d4da40f88693c29f2a3e6e90
sha256: 12a570db66717ae4f40d2d0c67367cb12012b79a20262aa5cee495185f158ee9
sha512: acaaa1e2c89832e4aaa9e0d34233528103464e45ece9172edf500db35b6ef7de29f722e2dcced1e5516ac332e414bf36a6f2f361f527b01856f9eff039698093
ssdeep: 1536:nhaIptJrGQBn74HLElkVAQ3Dq5rSHjKlzpBqWerybn:nftVXBsHLaCXDKJpIWfn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5737B4A6AC74949DC1CC275847B36303C70FE752633CDA26ABC71BB6A73346846B362
sha3_384: 20e276b0332b823ed81b6d060620997f33d8e8e4f60beeb5f16091fe15f7ed0aed9e78529e9f76256aa33ccd5425371f
ep_bytes: 60be00f042008dbe0020fdff5783cdff
timestamp: 2008-10-23 14:09:35

Version Info:

Translation: 0x0804 0x04b0
Comments: 自动下载安装系统
CompanyName: Microsoft Corporation
FileDescription: 自动下载安装系统
ProductName: 自动下载安装系统
FileVersion: 5.01.2731
ProductVersion: 5.01.2731
InternalName: 工程1
OriginalFilename: 工程1.exe

Trojan-Spy.Win32.Vkont.wkj also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Fake.lc
McAfeeGeneric.dx!hv.g
ZillyaTrojan.VB.Win32.714
AlibabaTrojanSpy:Win32/Vkont.b1f7247f
VirITTrojan.Win32.VB.HBS
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
ClamAVWin.Trojan.Agent-447038
KasperskyTrojan-Spy.Win32.Vkont.wkj
NANO-AntivirusTrojan.Win32.VB.wwqi
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan-Spy.Vkont.Ijgl
F-SecureTrojan.TR/Crypt.FKM.Gen
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.c3a438a0882cece1
SophosMal/Behav-160
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminTrojan/VB.utg
GoogleDetected
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan/Win32.VB
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojan:Win32/DSSDetection
XcitiumMalware@#27boyxi0irtba
ZoneAlarmTrojan-Spy.Win32.Vkont.wkj
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.C37643
BitDefenderThetaAI:Packer.6D70569A20
Cylanceunsafe
PandaAdware/AccesMembre
RisingSpyware.Vkont!8.1A96 (CLOUD)
YandexTrojan.VB!TwmmdtuP9z4
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.777288.susgen
FortinetW32/VB.HBS!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[spy]:Win/Vkont.wkj

How to remove Trojan-Spy.Win32.Vkont.wkj?

Trojan-Spy.Win32.Vkont.wkj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment