Trojan

Should I remove “Trojan.Win32.VBKrypt.xabo”?

Malware Removal

The Trojan.Win32.VBKrypt.xabo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VBKrypt.xabo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Albanian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.VBKrypt.xabo?


File Info:

name: BD628BF677C510CC4F53.mlw
path: /opt/CAPEv2/storage/binaries/5fd226400a95f330fdee18fb38e84f419b9233289a10ba0b07b6c3a87a106aa0
crc32: 8A7ABC4A
md5: bd628bf677c510cc4f5362ab79545320
sha1: c942c805692a8e50bb8c85a11aecf3f19d59e707
sha256: 5fd226400a95f330fdee18fb38e84f419b9233289a10ba0b07b6c3a87a106aa0
sha512: 08fd183ea65ac1ddca8948d9467fddaafd4caac9d0de7f16fd630b46cffe16e09575301c0082b5abce5110259c64480086614ed388f6fb3e504232c72c8e2c1a
ssdeep: 3072:W6Ccn27mUC7AdYzrV+Dljy/32ubwZZqJ:W6Ccn2xCkdYzrVolu/J0ZZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130A3F141BF34D2ABD73D577AC6322EB696A27C96A966D0CCE7F836CF4470110C05E84A
sha3_384: 363e90d10c6170113b208828d6d85e510d1cd5b894287cbf0a0936971c34780d94da832ef3092860ad444750d08680bf
ep_bytes: 60be002042008dbe00f0fdff57eb0b90
timestamp: 2012-05-21 22:42:06

Version Info:

Translation: 0x0409 0x04b0
Comments: Devoto qs medico
CompanyName: attuo tn
FileDescription: Tronco jp false mance
LegalCopyright: cesoia sbendo gm
LegalTrademarks: sicure ah
ProductName: piango
FileVersion: 5.05.0008
ProductVersion: 5.05.0008
InternalName: alta
OriginalFilename: alta.exe

Trojan.Win32.VBKrypt.xabo also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebBackDoor.Umbra.10
MicroWorld-eScanGen:Heur.PonyStealer.MLT.1
CAT-QuickHealTrojan.VbkryptVMF.S19740945
SkyhighGenericR-IHT!9B991C6CD25F
McAfeeGenericR-IHT!9B991C6CD25F
MalwarebytesGeneric.Trojan.Delf.DDS
ZillyaTrojan.VBKrypt.Win32.834887
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0053251e1 )
K7AntiVirusTrojan ( 0053251e1 )
BitDefenderThetaGen:NN.ZevbaF.36804.gmKfayPV1!gG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.UHJ
APEXMalicious
KasperskyTrojan.Win32.VBKrypt.xabo
BitDefenderGen:Heur.PonyStealer.MLT.1
NANO-AntivirusTrojan.Win32.Umbra.efkzrr
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10bfd3d6
EmsisoftGen:Heur.PonyStealer.MLT.1 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Heur.PonyStealer.MLT.1
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bd628bf677c510cc
SophosMal/Behav-405
IkarusTrojan.Win32.Jorik
JiangminTrojan/VBKrypt.hmyy
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/VBKrypt.BLI.gen!Eldorado
Antiy-AVLTrojan/Win32.Delf
Kingsoftmalware.kb.b.1000
MicrosoftTrojanDownloader:Win32/Umbald.A
XcitiumTrojWare.Win32.Injector.SOJC@4ppnjv
ArcabitTrojan.PonyStealer.MLT.1
ZoneAlarmTrojan.Win32.VBKrypt.xabo
GDataGen:Heur.PonyStealer.MLT.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.VBKrypt.R638994
VBA32TScope.Trojan.VB
TACHYONTrojan/W32.Agent.147456
Cylanceunsafe
PandaGeneric Malware
RisingDownloader.Umbald!8.3E4 (C64:YzY0OgSEFJtfnbzi)
YandexTrojan.GenAsa!KkjeiCKtmVA
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.MBSX!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.VBKrypt.xabo?

Trojan.Win32.VBKrypt.xabo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment