Trojan

Trojan.Win32.VBKrypt.zkjt removal

Malware Removal

The Trojan.Win32.VBKrypt.zkjt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.VBKrypt.zkjt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.VBKrypt.zkjt?


File Info:

crc32: AAB06D69
md5: 5530e8dcb60d0dcc68fe18810bb9e53c
name: 5530E8DCB60D0DCC68FE18810BB9E53C.mlw
sha1: 0addb140b908fd95f1efdc26e9b90975d1b55b9f
sha256: 24f0d922d0dbd20647e6c89d86b1dec6aac2316833d338dcf9eea7dff0a1c2b1
sha512: 1c360cb33a8bf968ba492cdad811bc06cd7f4fdb59617b20e902e2254fc2d9bdff6e2ffca3d60f6b6a5310a15e5f2cea0a3aa61b5f93608f2ede64a9dfb8ec24
ssdeep: 12288:04TZJHtqPRx+9Bvw6VjWVmzafcWf/rKpHGAcKEZUiX:0mJHjDpiNnGpHGFPZUi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: GJSe 'computiNG FORceo'
InternalName: Bathypelagic
FileVersion: 1.07
LegalTrademarks: ePSON
Comments: HEA Ve TOop soft war
ProductName: tie kOSSA
ProductVersion: 1.07
OriginalFilename: Bathypelagic.exe

Trojan.Win32.VBKrypt.zkjt also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052f9e21 )
Elasticmalicious (high confidence)
ClamAVWin.Downloader.LokiBot-9165134-0
ALYacGen:Heur.PonyStealer.On0@d0rh!Cii
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.299213
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0052f9e21 )
Cybereasonmalicious.cb60d0
SymantecPacked.Generic.531
ESET-NOD32a variant of Win32/Injector.DXTP
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VBKrypt.zkjt
BitDefenderGen:Heur.PonyStealer.On0@d0rh!Cii
NANO-AntivirusTrojan.Win32.VBKrypt.fbeges
MicroWorld-eScanGen:Heur.PonyStealer.On0@d0rh!Cii
Ad-AwareGen:Heur.PonyStealer.On0@d0rh!Cii
SophosML/PE-A + Mal/FareitVB-AB
BitDefenderThetaGen:NN.ZevbaF.34796.On0@a0rh!Cii
TrendMicroTSPY_HPLOKI.SMVBMP0
McAfee-GW-EditionBehavesLike.Win32.Trojan.tz
FireEyeGeneric.mg.5530e8dcb60d0dcc
EmsisoftGen:Heur.PonyStealer.On0@d0rh!Cii (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.VBKrypt.eqjn
AviraHEUR/AGEN.1117871
MicrosoftVirTool:Win32/VBInject.AHV!bit
GDataGen:Heur.PonyStealer.On0@d0rh!Cii
TACHYONTrojan/W32.Inject.1703936
AhnLab-V3Win-Trojan/VBKrypt.RP12.X2026
McAfeeGenericRXPG-ZY!5530E8DCB60D
MAXmalware (ai score=86)
VBA32Trojan.VBKrypt
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_HPLOKI.SMVBMP0
RisingTrojan.Injector!1.B459 (CLASSIC)
FortinetW32/GenKryptik.CBCD!tr
AVGWin32:Trojan-gen
Qihoo-360HEUR/QVM03.0.AB77.Malware.Gen

How to remove Trojan.Win32.VBKrypt.zkjt?

Trojan.Win32.VBKrypt.zkjt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment