Trojan

Trojan.VBCryptMF.S29949104 removal instruction

Malware Removal

The Trojan.VBCryptMF.S29949104 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VBCryptMF.S29949104 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with Y0da
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.VBCryptMF.S29949104?


File Info:

name: FE145E927BFBC10A57DA.mlw
path: /opt/CAPEv2/storage/binaries/8a69190229e5c7afd66e8bb2605157a691ad3b1925ebec44266659f4efbfc9c0
crc32: A726FB3A
md5: fe145e927bfbc10a57da670a2707f2db
sha1: 1c158762591e66c54de51f4dca9e0639f83f550c
sha256: 8a69190229e5c7afd66e8bb2605157a691ad3b1925ebec44266659f4efbfc9c0
sha512: 464e73840a545bdccd5789f708ffdc3731b43e0f6d22336705950653993452462e5dfc2cb72583a925e248148ff716d3ec3a5e3a822b5aae067aa79b2616517e
ssdeep: 6144:fBgJib4gfGWcmsQ+/gbG0xlfPpndiVPxqoU:OJXZa+/gbGUXBdiVJE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17464B3527E324009DAD405702BD2B1D96EEB34995A17470ABA2425287FEFD473CE1FCB
sha3_384: dfc33a410c4457ddc21de2aa9b9185fd3d4ce77172e9956754aa8fbd9924f98bc41ca168c3af87fce3126680544d5fec
ep_bytes: 6820134000e8eeffffff000000000000
timestamp: 2012-05-11 16:10:55

Version Info:

Translation: 0x0409 0x04b0
ProductName: jbzdmrbcjcidl
FileVersion: 3.08.0006
ProductVersion: 3.08.0006
InternalName: izszgnrg
OriginalFilename: izszgnrg.exe

Trojan.VBCryptMF.S29949104 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner1.34235
MicroWorld-eScanGen:Variant.Barys.2490
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.fe145e927bfbc10a
CAT-QuickHealTrojan.VBCryptMF.S29949104
ALYacGen:Variant.Barys.2490
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.2591e6
BitDefenderThetaGen:NN.ZevbaF.36662.tu0@aanqEwoi
VirITWorm.Win32.X-Aurun.BYQT
CyrenW32/S-f824b88f!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.AQ
ZonerWorm.Win32.477
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Barys.2490
NANO-AntivirusTrojan.Win32.bglijn.eanvxd
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastSf:ShellCode-DX [Trj]
TencentTrojan.Win32.Jorik.hh
TACHYONTrojan/W32.VB-Jorik.316416
SophosW32/Vobfus-AH
F-SecureTrojan.TR/Jorik.cvtkya
BaiduWin32.Worm.Pronny.gn
VIPREGen:Variant.Barys.2490
TrendMicroWORM_VOBFUS.SMD5
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.2490 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10T9JN3
WebrootW32.Obfuscated.Gen
AviraTR/Jorik.cvtkya
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.D9BA
ViRobotTrojan.Win32.Jorik.307200.A
ZoneAlarmTrojan.Win32.Jorik.Vobfus.cvtk
MicrosoftWorm:Win32/Vobfus.FB
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R361947
McAfeeVBObfus.dv
MAXmalware (ai score=85)
VBA32Trojan.Jorik
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEV.worm
TrendMicro-HouseCallWORM_VOBFUS.SMD5
RisingWorm.Pronny!1.AE42 (CLASSIC)
YandexTrojan.GenAsa!JXJIOxYljXk
IkarusTrojan.Win32.Jorik
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Jorik.EGLG!tr
AVGSf:ShellCode-DX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.VBCryptMF.S29949104?

Trojan.VBCryptMF.S29949104 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment