Trojan

Should I remove “Trojan.Win32.VBKrypt.otbe”?

Malware Removal

The Trojan.Win32.VBKrypt.otbe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VBKrypt.otbe virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Trojan.Win32.VBKrypt.otbe?


File Info:

name: E5B60F79250AADC95BE3.mlw
path: /opt/CAPEv2/storage/binaries/cfbe00d3ea7001fecc81d5d12e140cb170c74dca2514baacdef0ae62fec2b98d
crc32: C8C63A36
md5: e5b60f79250aadc95be3827286f9957b
sha1: dadcebe896388db81bf4e0175d2ed8b17e8a9187
sha256: cfbe00d3ea7001fecc81d5d12e140cb170c74dca2514baacdef0ae62fec2b98d
sha512: a97116e9b5fc7d5a60a0463ddb79d16bf9218b689bf79df6649777fc4250a92a281f9414f4b69798dcc60584476312eb5361979089c54ddd3ff984b06bb2e0bd
ssdeep: 98304:zHZNTr6+F8FSkaErHskUSSnnYlwCDLpu4zvsO:zzTrWSIrHu9+DLpuaUO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128E533ADF6B45C9DDB3AF3BA1180B02694C97FE5671E56C718D9E4040AEA07D2F36C02
sha3_384: 28ae65ed86fe26f3572302c10f089c33daf175c67e781d6da1a37df1a464d093282b375100f15805cfd560bc6c14885e
ep_bytes: 558bec81ec2c0500005356576a015e6a
timestamp: 2000-04-25 14:37:12

Version Info:

CompanyName: AFIP
FileDescription: KIT MARIA
FileVersion: SIM 2.99.1
LegalCopyright: AFIP

Trojan.Win32.VBKrypt.otbe also known as:

LionicTrojan.Win32.VBKrypt.4!c
MicroWorld-eScanTrojan.GenericKD.30412071
FireEyeTrojan.GenericKD.30412071
ALYacTrojan.GenericKD.30412071
CylanceUnsafe
SangforTrojan.Win32.Skeeyah.A
AlibabaTrojan:Win32/VBKrypt.e94c120a
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecTrojan.Gen.2
KasperskyTrojan.Win32.VBKrypt.otbe
BitDefenderTrojan.GenericKD.30412071
NANO-AntivirusTrojan.Win32.VBKrypt.bhtamk
AvastWin32:Malware-gen
TencentWin32.Trojan.Vbkrypt.Alik
TACHYONTrojan/W32.VBKrypt.3163747
EmsisoftTrojan.GenericKD.30412071 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Skeeyah
GDataTrojan.GenericKD.30412071
MicrosoftTrojan:Win32/Skeeyah.A!bit
McAfeeArtemis!E5B60F79250A
MAXmalware (ai score=100)
VBA32Trojan.VBKrypt
MalwarebytesMalware.AI.3802658114
YandexTrojan.VBKrypt!lzCpMSAVlJc
FortinetW32/VBKrypt.OTBE!tr
AVGWin32:Malware-gen
Cybereasonmalicious.9250aa
PandaTrj/CI.A

How to remove Trojan.Win32.VBKrypt.otbe?

Trojan.Win32.VBKrypt.otbe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment