Malware

VirTool:Win32/VBInject.YA!MTB (file analysis)

Malware Removal

The VirTool:Win32/VBInject.YA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.YA!MTB virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Czech
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine VirTool:Win32/VBInject.YA!MTB?


File Info:

crc32: 455B8806
md5: bf91b5849a091111ddc49dfaf58f5ebd
name: upload_file
sha1: e3d233a6f3ab8664afa6d9986121ce11e1b09d71
sha256: ab703a3bc7d05c62bcc127febfd82a7903a47f45664b5195ada070eb748d5b25
sha512: 2b4571c3785390f84b6b2cf3b3391d0c4a68e868a0ed4915eea6ed03e418b85d5e731abc78bc6de6e1117c8bf9fd5c2f6a53e4d84fee331862af6f0df26c9ee2
ssdeep: 24576:ycCT67wHqWis4l+jIACFr5hqjiLDpSJDN93pqb6W8cU4gLQ2A:DCpn8t74iA3qb6W8cU4F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0405 0x04b0
InternalName: Braggat0
FileVersion: 1.09.0005
CompanyName: Windows
Comments: Geacata
ProductName: Orphancy
ProductVersion: 1.09.0005
FileDescription: Geacata
OriginalFilename: Braggat0.exe

VirTool:Win32/VBInject.YA!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DXTX
FireEyeGeneric.mg.bf91b5849a091111
McAfeeDistTrack!BF91B5849A09
ZillyaTrojan.VBKrypt.Win32.302131
SangforMalware
K7AntiVirusTrojan ( 00502b1a1 )
BitDefenderTrojan.Agent.DXTX
K7GWTrojan ( 00502b1a1 )
CrowdStrikewin/malicious_confidence_100% (D)
Invinceaheuristic
F-ProtW32/Injector.GRK
SymantecW32.Tapin
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.Ponystealer-6733035-0
KasperskyTrojan.Win32.VBKrypt.xupa
AlibabaWorm:Win32/VBKrypt.40f123d4
NANO-AntivirusTrojan.Win32.VBKrypt.ewdbrj
RisingWorm.Autorun!8.50 (TFE:dGZlOgMoz0u8RDK7zQ)
Ad-AwareTrojan.Agent.DXTX
ComodoTrojWare.Win32.Fareit.RGY@7qlz41
F-SecureHeuristic.HEUR/AGEN.1126331
DrWebTrojan.Siggen6.55368
TrendMicroTSPY_HPFAREIT.SME
FortinetW32/Injector.DJYO!tr
SophosMal/FareitVB-I
IkarusWorm.Win32.AutoRun
CyrenW32/Injector.YKAB-2853
JiangminTrojan.VBKrypt.cgtc
WebrootW32.Gen.Bt
AviraHEUR/AGEN.1126331
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.VBKrypt
ArcabitTrojan.Agent.DXTX
SUPERAntiSpywareTrojan.Agent/Gen-PonyStealer
ZoneAlarmTrojan.Win32.VBKrypt.xupa
MicrosoftVirTool:Win32/VBInject.YA!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP08.X1976
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34182.Gn0@aOomUhlO
ALYacTrojan.Agent.DXTX
TACHYONTrojan/W32.VB-VBKrypt.1576960.B
VBA32Trojan.VBKrypt
MalwarebytesSpyware.Pony
PandaTrj/Genetic.gen
ZonerTrojan.Win32.82457
ESET-NOD32Win32/AutoRun.Delf.LV
TrendMicro-HouseCallTSPY_HPFAREIT.SME
TencentMalware.Win32.Gencirc.10b09472
SentinelOneDFI – Malicious PE
GDataTrojan.Agent.DXTX
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.49a091
Qihoo-360HEUR/QVM03.0.5A1B.Malware.Gen

How to remove VirTool:Win32/VBInject.YA!MTB?

VirTool:Win32/VBInject.YA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment