Trojan

Trojan.Win32.VBKrypt.vqmh (file analysis)

Malware Removal

The Trojan.Win32.VBKrypt.vqmh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VBKrypt.vqmh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Trojan.Win32.VBKrypt.vqmh?


File Info:

name: AEEAD7F177D5F4058711.mlw
path: /opt/CAPEv2/storage/binaries/65eb2a1bc083410d154d30f1ceb08c64f5a6d4c37b30eb9c59496aaff9f21793
crc32: 636EB7FF
md5: aeead7f177d5f40587114f0f0e3c4ab2
sha1: 8818fae3cd289f05f08c83f3995a1548605dc9b8
sha256: 65eb2a1bc083410d154d30f1ceb08c64f5a6d4c37b30eb9c59496aaff9f21793
sha512: 97ec802005494754f9c1ee7974e2000fd2e2e30a99f23d9dd2bd18fe48cec06015c9e80798f9eafa49f5ae1fa68c127352e047d414bde3a7a2b32ff181ef45f3
ssdeep: 49152:Twcq+czRQ5fqSLXs/lJ7IAzDcLSwfE5E/wSWrEvnBq0WX:TwcuRQ5fpLXs/n10SlT4Hc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12195C013E6907226EE52D5713058A3B93818AF352219A807B780DE745B71AF7BE7C337
sha3_384: 38653713dcae98da1a52bfd04a302d596231dff24881c2fc114158b880614236d7377be467488ba83b30ae504bbee435
ep_bytes: 5589e5e80c0000005dc3cccccccccce8
timestamp: 2012-01-02 16:40:01

Version Info:

Translation: 0x0409 0x04b0
CompanyName: DG2KBC
ProductName: Project1
FileVersion: 0.02.0006
ProductVersion: 0.02.0006
InternalName: Project1
OriginalFilename: Project1.exe

Trojan.Win32.VBKrypt.vqmh also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.VBKrypt.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44484586
ALYacTrojan.GenericKD.44484586
CylanceUnsafe
SangforTrojan.Win32.VBKrypt.8
K7AntiVirusTrojan ( 004c12061 )
AlibabaTrojan:Win32/VBKrypt.46881b01
K7GWTrojan ( 004c12061 )
Cybereasonmalicious.177d5f
BitDefenderThetaGen:NN.ZexaF.34084.3r3@augj9Ifi
CyrenW32/Agent.CC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.MoleboxUltra suspicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9878032-0
KasperskyTrojan.Win32.VBKrypt.vqmh
BitDefenderTrojan.GenericKD.44484586
NANO-AntivirusTrojan.Win32.VBKrypt.eqqbvi
AvastWin32:Malware-gen
TencentWin32.Trojan.Vbkrypt.Lscg
Ad-AwareTrojan.GenericKD.44484586
EmsisoftTrojan.GenericKD.44484586 (B)
ComodoMalware@#xx4d57o7mdu9
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.aeead7f177d5f405
SophosMal/Generic-S
GDataTrojan.GenericKD.44484586
JiangminTrojan.VBKrypt.axrw
ArcabitTrojan.Generic.D2A6C7EA
MicrosoftTrojan:MSIL/Cryptor
McAfeeArtemis!AEEAD7F177D5
MAXmalware (ai score=88)
VBA32Backdoor.Bladabindi
APEXMalicious
RisingTrojan.Generic@ML.100 (RDML:DcwvnHLaZI6FAZF73sCshg)
YandexTrojan.VBKrypt!Jp60sFFyBcI
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
AVGWin32:Malware-gen
PandaGeneric Suspicious

How to remove Trojan.Win32.VBKrypt.vqmh?

Trojan.Win32.VBKrypt.vqmh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment