Trojan

Trojan.Win32.VBKrypt.vmdu malicious file

Malware Removal

The Trojan.Win32.VBKrypt.vmdu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VBKrypt.vmdu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Trojan.Win32.VBKrypt.vmdu?


File Info:

name: 2676240B817A6035642C.mlw
path: /opt/CAPEv2/storage/binaries/72f36307ecf37163e5c16568a4e636fde1c5058fd0c59aaad4f33b6aef7b0b62
crc32: C4FCD2D9
md5: 2676240b817a6035642cbacf22bfc1f0
sha1: 51f13eb0bd6a79c37cc9175aa50b88320e935e43
sha256: 72f36307ecf37163e5c16568a4e636fde1c5058fd0c59aaad4f33b6aef7b0b62
sha512: ae2e3c8565c82af5173c30dd9a5c05175bd7861c5243e647c22c770d0bde86c2d5f31f946fdc5fa44010c7d56432e9d2dfa15a24566a3af67a5e784a8ee967f7
ssdeep: 96:kpFct8xEG9kaH+o1jWTHPO+bzFb7peyZoM2:oFct8xE4tW2wAM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111728406F798D0AAF2A65B315D53CBF992367C204F2A491B76843B2F7C70680DD66E43
sha3_384: 420a4b1aa38a54311ecb856520bcd2ce03fba6b1418a411da9ed34e817072e299cb779358cad057ef7edab54bfcf22bf
ep_bytes: 68d4104000e8f0ffffff000000000000
timestamp: 2010-03-08 12:05:39

Version Info:

Translation: 0x0409 0x04b0
Comments: QaaZe
CompanyName: moxHCgvNiBv
FileDescription: EQTrMlrnzC
LegalCopyright: KsJvzaN
LegalTrademarks: HOtGFVZcTs
ProductName: AkSUpRQku
FileVersion: 3.39.0020
ProductVersion: 3.39.0020
InternalName: Stub
OriginalFilename: Stub.exe

Trojan.Win32.VBKrypt.vmdu also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vobfus.lVmF
Elasticmalicious (high confidence)
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
AlibabaTrojan:Win32/VBKrypt.80992544
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaAI:Packer.582BFAA320
SymantecTrojan.Gen.MBT
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.VBKrypt.vmdu
NANO-AntivirusTrojan.Win32.TrjGen.bwmmaf
TencentWin32.Trojan.Vbkrypt.Kqil
F-SecureTrojan.TR/VB.Downloader.Gen
DrWebTrojan.Siggen4.20010
TrendMicroTROJ_GEN.R26E1GE
SophosMal/Generic-S
IkarusTrojan.Injector
GoogleDetected
AviraTR/VB.Downloader.Gen
Antiy-AVLTrojan/Win32.Generic
Kingsoftmalware.kb.a.964
XcitiumTrojWare.Win32.VB.fmmu@4aq4ot
ZoneAlarmTrojan.Win32.VBKrypt.vmdu
VaristW32/VB-Downloader-Minimi-based!
VBA32Malware-Cryptor.VB.gen.1
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R26E1GE
RisingTrojan.VBKrypt!8.5C0 (CLOUD)
YandexTrojan.Agent!jjcwZyCvSoE
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Dx.R26E1GE!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:MSOffice/VBKrypt.vmdu

How to remove Trojan.Win32.VBKrypt.vmdu?

Trojan.Win32.VBKrypt.vmdu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment