Trojan

Trojan.VBCrypt.MF.139 malicious file

Malware Removal

The Trojan.VBCrypt.MF.139 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VBCrypt.MF.139 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.VBCrypt.MF.139?


File Info:

name: 3C13865105BD89158B14.mlw
path: /opt/CAPEv2/storage/binaries/106308ab04c483f2ec2a3d26f4642b788d4110782107a468daec06a508117190
crc32: 26DAA78F
md5: 3c13865105bd89158b14da37e48b4511
sha1: 714ae1bf1123c673da3ffe0a762631b5bfb4aafc
sha256: 106308ab04c483f2ec2a3d26f4642b788d4110782107a468daec06a508117190
sha512: a184f99bd08c8cbd59e804ee60198a486170c80d61e58da0ded1a855ab63a541f8ea85e85b379bc9c59b6decd7a7960790642b5b4b24bb8eb9646fa406538363
ssdeep: 768:gFPXwasz7tsMuzeBsTBkbHrHXd4fCJcEHwzOx0vc:gdM6MRsTB4bqh1vc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11003962E7359C839FB49763B324BB6D711EBF0A89B8B26827519377AD811F091C12743
sha3_384: 18940edf7263f6497465ad16830f0cbb3acc249397fa1ef2614ee400e77856e5f4f15bab3941698cec08669141678d61
ep_bytes: 68ec114000e8eeffffff000000000000
timestamp: 2000-01-01 12:00:00

Version Info:

Translation: 0x0409 0x04b0

Trojan.VBCrypt.MF.139 also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-AYY [Wrm]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.2
FireEyeGeneric.mg.3c13865105bd8915
CAT-QuickHealTrojan.VBCrypt.MF.139
SkyhighBehavesLike.Win32.VBObfus.pt
McAfeeVBObfus
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.VBNA.Win32.124573
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 00568ea21 )
K7GWTrojan ( 0056e0ad1 )
BitDefenderThetaAI:Packer.B88CE64F20
VirITWorm.Win32.VB.JH
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.FJ
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:AutoRun-AYY [Wrm]
ClamAVWin.Trojan.Chinky-20
KasperskyWorm.Win32.VBNA.fcb
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.VB.crkznv
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
RisingWorm.Vobfus!8.10E (TFE:3:1ONF5whgplF)
EmsisoftGen:Trojan.Chinky.2 (B)
BaiduWin32.Worm.VB.qt
F-SecureWorm:W32/Datunif.A
DrWebTrojan.MulDrop4.4114
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_JER.G
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Chinky.2
JiangminWorm/VBNA.hajp
VaristW32/VBTrojan.6!Maximus
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.VBNA
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDropper.Multi.TD5@1ej370
ArcabitTrojan.Chinky.2
ViRobotWorm.Win32.VBNA.40960.ABG
ZoneAlarmWorm.Win32.VBNA.fcb
MicrosoftWorm:Win32/Vobfus.F
GoogleDetected
AhnLab-V3Worm/Win32.Basun.R1388
Acronissuspicious
VBA32SScope.Trojan.VB.Svchorse.031
ALYacGen:Trojan.Chinky.2
Cylanceunsafe
PandaW32/Vobfus.gen.worm
TrendMicro-HouseCallWORM_JER.G
TencentWorm.Win32.Vbna.fd
YandexTrojan.GenAsa!P8NjBhAvZ88
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.fa3c71a3

How to remove Trojan.VBCrypt.MF.139?

Trojan.VBCrypt.MF.139 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment