Trojan

How to remove “Trojan.VBCryptMF.S29949157”?

Malware Removal

The Trojan.VBCryptMF.S29949157 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VBCryptMF.S29949157 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.VBCryptMF.S29949157?


File Info:

name: 24194A4A8BAA61BC15B2.mlw
path: /opt/CAPEv2/storage/binaries/6eb949cf8da3434f3116921610f93a9d099e5c42ef8f00172160e5dd04ec16a0
crc32: 741AA077
md5: 24194a4a8baa61bc15b2afd89b4262f4
sha1: 2e5d346418c07e1887592db1feb274f769428045
sha256: 6eb949cf8da3434f3116921610f93a9d099e5c42ef8f00172160e5dd04ec16a0
sha512: a610856f112faee002038be4bb1d6e48b2c3a7da26d0ffcf9c7cfc63832dd3ae77b1490416780e3881c984d61d2474aa437dce372b2097b370ab52a809735a9c
ssdeep: 1536:YNszJ5YpJWlhRO/N69BH3OoGa+FL9jKceRgrkjSo:GGnYpJAhkFoN3Oo1+F92S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134C3B9BAFB81507DF596417C16EAE6F337A27048CD6BC085A634A2A44CDAD120CFDB53
sha3_384: 50af8a71cb9ecedd66b437a9102b396e9c5b08b258726f03e81eecf7c8c91593a948a5210c042579cb2d24649c7e71aa
ep_bytes: 6880124000e8eeffffff000048000000
timestamp: 2012-04-10 21:59:09

Version Info:

0: [No Data]

Trojan.VBCryptMF.S29949157 also known as:

BkavW32.FamVT.JorikHQc.Trojan
LionicWorm.Win32.Vobfus.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.FFVY
ClamAVWin.Dropper.XtremeRAT-7708589-0
FireEyeGeneric.mg.24194a4a8baa61bc
CAT-QuickHealTrojan.VBCryptMF.S29949157
McAfeeVBObfus.ds
Cylanceunsafe
ZillyaTrojan.JorikGen.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/vobfus.12e3e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a8baa6
BaiduWin32.Worm.Autorun.u
VirITTrojan.Win32.Generic.KN
CyrenW32/Vobfus.AO.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.Agent.ATZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.aiez
BitDefenderTrojan.Agent.FFVY
NANO-AntivirusTrojan.Win32.Autoruner.cihufu
SUPERAntiSpywareWorm.Vobfus
AvastWin32:VB-ACGX [Trj]
TencentWorm.Win32.Vobfus.ka
TACHYONWorm/W32.Vobfus.126976
EmsisoftTrojan.Agent.FFVY (B)
F-SecureTrojan.TR/Jorik.Vobfus.ajr
DrWebWin32.HLLW.Autoruner2.29121
VIPRETrojan.Agent.FFVY
TrendMicroTROJ_AGENT_031859.TOMB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminemalicious.high.ml.score
SophosTroj/Vb-FWD
IkarusTrojan.Crypt
GDataTrojan.Agent.FFVY
JiangminTrojan/Jorik.gjym
AviraTR/Jorik.Vobfus.ajr
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AD@4omzqe
ArcabitTrojan.Agent.FFVY
ViRobotTrojan.Win32.Vobfus.126976
ZoneAlarmWorm.Win32.Vobfus.aiez
MicrosoftWorm:Win32/Vobfus.EK
GoogleDetected
AhnLab-V3Trojan/Win32.Vobfus.R37780
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36250.hmW@aeY4N6i
ALYacTrojan.Agent.FFVY
MAXmalware (ai score=82)
VBA32SScope.Malware-Cryptor.VBCR.1141
MalwarebytesMalware.AI.3595163589
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_AGENT_031859.TOMB
RisingWorm.VobfusEx!1.99E1 (CLASSIC)
YandexTrojan.GenAsa!NQ5jghRmwiA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACGX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.VBCryptMF.S29949157?

Trojan.VBCryptMF.S29949157 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment