Trojan

Should I remove “Trojan.Win32.VBKrypt.jctj”?

Malware Removal

The Trojan.Win32.VBKrypt.jctj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VBKrypt.jctj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.VBKrypt.jctj?


File Info:

name: A15310233A7A8CE524F5.mlw
path: /opt/CAPEv2/storage/binaries/ab10ccdd4f1a0b12f0ff428a22eddf7b11653eac9dda7965d6102f48bbaef0ac
crc32: A47B8AFA
md5: a15310233a7a8ce524f5dac071be889b
sha1: 168c60c4ed6abb4c19c7bead50c6a1d3b27a1b82
sha256: ab10ccdd4f1a0b12f0ff428a22eddf7b11653eac9dda7965d6102f48bbaef0ac
sha512: bed38bb54fd65230f9788f08586929bf281c102a394f29f87961278e42cb81ffdabb7398ba87807a1fcaade5e54fa2328bffaf50651931fd3de70c843309b4bf
ssdeep: 6144:rpSuUPH3bX2a23NYcJQ8TfxZ85WJ007G9tSBN70:rpSuUPH3bX2a23NYcJQ8TfxZ9J0rtSzQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E234D53EB250A73EE156C6F52CAE8794402DAD3A15C0A447F7D22F6A76F19B38132347
sha3_384: ba160e6127fdffefd56029848268a745d4c47b386e415e4dcaf28b2a2f68ab07b31047532c1604de02fb45d00cfef18f
ep_bytes: 68403d4000e8f0ffffff000000000000
timestamp: 1996-10-24 23:07:49

Version Info:

0: [No Data]

Trojan.Win32.VBKrypt.jctj also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.miMq
MicroWorld-eScanGen:Variant.Barys.62377
ClamAVWin.Trojan.VB-1613
FireEyeGeneric.mg.a15310233a7a8ce5
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.df
MalwarebytesMalware.AI.1489267714
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.SHeur4.PNG
CyrenW32/Vobfus.SL.gen!Eldorado
SymantecW32.Changeup!gen35
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ARS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VBKrypt.jctj
BitDefenderGen:Variant.Barys.62377
NANO-AntivirusTrojan.Win32.WBNA.chzvjj
AvastWin32:VB-ABAV [Trj]
TencentTrojan.Win32.Vb.kc
TACHYONTrojan/W32.VB-VBKrypt.233472.AK
EmsisoftGen:Variant.Barys.62377 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Barys.62377
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dt
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.62377
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Barys.DF3A9
ZoneAlarmTrojan.Win32.VBKrypt.jctj
MicrosoftWorm:Win32/Vobfus.gen!T
GoogleDetected
AhnLab-V3Trojan/Win.VBKrypt.R558887
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36250.omY@aWwscCb
ALYacGen:Variant.Barys.62377
MAXmalware (ai score=85)
VBA32BScope.Malware-Cryptor.VBCR.7212
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Autorun!1.99EA (CLASSIC)
YandexTrojan.GenAsa!QrKV+ICVvgE
IkarusTrojan.Win32.Otran
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.AZGU!tr
AVGWin32:VB-ABAV [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.VBKrypt.jctj?

Trojan.Win32.VBKrypt.jctj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment