Malware

What is “VirTool:Win32/Vbcrypt”?

Malware Removal

The VirTool:Win32/Vbcrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Vbcrypt virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify browser security settings
  • Attempts to disable UAC

How to determine VirTool:Win32/Vbcrypt?


File Info:

crc32: 3DE661F6
md5: f7623aa3eb4e7cc718ec138d75daee37
name: F7623AA3EB4E7CC718EC138D75DAEE37.mlw
sha1: d78eaf67413ad7579fe618bbdc96cfb892c416f5
sha256: fd940553f6d603b6e083f6b7d8dc4432d39d96ae58c3d03d685fc90178e8dd36
sha512: e194bf8980f2a2664ef4e6b37386fa0ac4b8977003881b0dbf8adc0c8ccdc498c42384a5acd8286779e04af07e817890728af9949bd8859db66f491676a28c06
ssdeep: 384:/TQ0yIk9m7S7TBzLOrQC0/xbdAfayH/dEU4:/JyIu/7Torn4pKiyfqU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: haoaKMjoj
InternalName: yfdkcljgl
FileVersion: 2.40.0097
CompanyName: haoaKMjoj
LegalTrademarks: haoaKMjoj
ProductName: wtgUwxVLHZXP
ProductVersion: 2.40.0097
FileDescription: boOpJSNDCAm
OriginalFilename: yfdkcljgl.exe

VirTool:Win32/Vbcrypt also known as:

DrWebWorm.Siggen.5400
MicroWorld-eScanGen:Variant.Razy.830603
FireEyeGen:Variant.Razy.830603
CAT-QuickHealTrojan.Graftor
ALYacGen:Variant.Razy.830603
CylanceUnsafe
VIPRELooksLike.Win32.Malware!vb (v)
SangforHacktool.Win32.Vbcrypt.mt
K7AntiVirusNetWorm ( 700000151 )
BitDefenderGen:Variant.Razy.830603
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.3eb4e7
BitDefenderThetaAI:Packer.A76699B520
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMetagen [Spy]
KasperskyTrojan.Win32.VB.cfpo
AlibabaTrojanSpy:Win32/Vbcrypt.9d5496a0
NANO-AntivirusTrojan.Win32.TrjGen.hpvgn
RisingSpyware.Bancos!8.2F8 (CLOUD)
Ad-AwareGen:Variant.Razy.830603
SophosMal/Generic-L
ComodoMalware@#2x4wkpb3i5yov
F-SecureTrojan.TR/Dropper.VB.Gen
ZillyaTrojan.VB.Win32.116193
TrendMicroTSPY_BANCOS.BGJ
McAfee-GW-EditionBehavesLike.Win32.YahLover.lh
EmsisoftGen:Variant.Razy.830603 (B)
JiangminTrojan.VB.ypx
WebrootW32.Malware.Gen
AviraTR/Dropper.VB.Gen
MAXmalware (ai score=85)
MicrosoftVirTool:Win32/Vbcrypt
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Razy.DCAC8B
ZoneAlarmTrojan.Win32.VB.cfpo
GDataGen:Variant.Razy.830603
CynetMalicious (score: 85)
AhnLab-V3Backdoor/Win32.Ciadoor.R64042
McAfeeArtemis!F7623AA3EB4E
VBA32BScope.TrojanDownloader.VB
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Spy.Bancos.OIX
TrendMicro-HouseCallTSPY_BANCOS.BGJ
TencentWin32.Trojan.Vb.Eddi
YandexTrojanSpy.Bancos!cRbcEJY0n7k
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMetagen [Spy]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/Malware.QVM11.Gen

How to remove VirTool:Win32/Vbcrypt?

VirTool:Win32/Vbcrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment