Categories: Malware

What is “VirTool:Win32/Vbcrypt.EF”?

The VirTool:Win32/Vbcrypt.EF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Vbcrypt.EF virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • A scripting utility was executed
  • A wscript.exe process commonly used in script or document file downloaders initiated network activity
  • Anomalous binary characteristics

Related domains:

lfg.ch4projects.com

How to determine VirTool:Win32/Vbcrypt.EF?


File Info:

crc32: 06B8E09Amd5: 99b40abed335a742b2ee4175feaf5fdaname: 99B40ABED335A742B2EE4175FEAF5FDA.mlwsha1: d84f13ed3812a2ed55386ff01e76f7d7126a58cesha256: 4f116e41c92d95ff910dba4a9152cd7974b12d623e845631bcfe6464b9cdc640sha512: dbac417b2a989321fc1dce8a4785934c2e6913c0b9334c2c7af5a3bc8122e34ca86a038efedcbd9f76d8b2dce15d8ea58bf7a8f64977a252b4dcbc92d5bb4970ssdeep: 12288:UwXWSckS0AlgR/P8T6PByQVldQpYQSqFSlkSqFS:U2TovlgJ8WY+9+Wn+type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/Vbcrypt.EF also known as:

Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Ransom.42
FireEye Generic.mg.99b40abed335a742
McAfee Artemis!99B40ABED335
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 7000000f1 )
BitDefender Gen:Variant.Ransom.42
K7GW Trojan ( 7000000f1 )
Cybereason malicious.ed335a
Symantec ML.Attribute.HighConfidence
APEX Malicious
Paloalto generic.ml
Kaspersky Trojan-Banker.Win32.Bancos.vfs
Alibaba TrojanBanker:Win32/Bancos.4a477c78
NANO-Antivirus Trojan.Script.Qhost.chhpdx
Rising Trojan.VB!8.B20 (CLOUD)
Ad-Aware Gen:Variant.Ransom.42
Sophos Mal/Generic-S
Comodo Malware@#307hm03u31fk4
F-Secure Dropper.DR/Delphi.Gen
DrWeb Trojan.Click3.19876
Zillya Trojan.Bancos.Win32.21473
TrendMicro TROJ_SPNR.04HO13
McAfee-GW-Edition GenericRXEN-JB!8E44E985B860
Emsisoft Gen:Variant.Ransom.42 (B)
Ikarus Trojan.VB
Jiangmin Trojan.Banker.Bancos.nr
Avira DR/Delphi.Gen
MAX malware (ai score=100)
Antiy-AVL Trojan[Banker]/Win32.Bancos
Kingsoft Win32.Troj.Banker.(kcloud)
Microsoft VirTool:Win32/Vbcrypt.EF
Arcabit Trojan.Ransom.42
AegisLab Trojan.Multi.Generic.4!c
ZoneAlarm Trojan-Banker.Win32.Bancos.vfs
GData Gen:Variant.Ransom.42
Cynet Malicious (score: 100)
BitDefenderTheta Gen:NN.ZelphiF.34590.GGW@aSsI8QoG
ALYac Gen:Variant.Ransom.42
VBA32 BScope.TrojanBanker.Bancos
Malwarebytes Malware.Heuristic.1006
Panda Trj/Agent.MIZ
ESET-NOD32 a variant of Win32/VB.QKE
TrendMicro-HouseCall TROJ_SPNR.04HO13
Tencent Win32.Trojan-banker.Bancos.Hwcq
Yandex Trojan.GenAsa!l39Cpy66DKA
Fortinet W32/Delf.AUQ!tr
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike win/malicious_confidence_60% (D)
Qihoo-360 Win32/TrojanPSW.Bancos.HgIASOkA

How to remove VirTool:Win32/Vbcrypt.EF?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Cerbu.190164 (file analysis)

The Cerbu.190164 is considered dangerous by lots of security experts. When this infection is active,…

1 min ago

Win32/Adware.Adposhel.AR information

The Win32/Adware.Adposhel.AR is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Trojan.Generic.35266640 malicious file

The Trojan.Generic.35266640 is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Should I remove “TrojanDownloader:Win32/Beebone.AC”?

The TrojanDownloader:Win32/Beebone.AC is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Mal/Swizzor-B removal tips

The Mal/Swizzor-B is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Adware.Hotbar.1 information

The Adware.Hotbar.1 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago