Trojan

What is “Trojan.VB.Refpron.1”?

Malware Removal

The Trojan.VB.Refpron.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VB.Refpron.1 virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Trojan.VB.Refpron.1?


File Info:

crc32: 2366C49A
md5: 7fb2ec1d7768db0b19cdd5098ebc5105
name: 7FB2EC1D7768DB0B19CDD5098EBC5105.mlw
sha1: 196073ace7891fe495b5c15f41ffe03a6cbd1f46
sha256: d9f18db2b43e9c4158cc5ea131167200a334cea009ff1f88596948c3d8827fe2
sha512: d6c697cc771cbd2d61700ffd58f6b45d4f86763b708e6b2d73715c5c3f3b8955e39679d19d5459c3185ba2053a1e3f67f70789040b4d92b68d6bfce7eef6f3b7
ssdeep: 192:5PwrOhz49R3EvKXFWhaTi5VY583X2qTBdLVeU9iNeE4oZ:ZcOhuBEyXFWhae5VAGDTnBEeaZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0407 0x04b0
LegalCopyright: rRnc2
InternalName: rewq
FileVersion: 7.36.0044
CompanyName: NYmD1ZzC
LegalTrademarks: eSpdr7u
Comments: mYHH
ProductName: swunnAM
ProductVersion: 7.36.0044
FileDescription: x
OriginalFilename: rewq.exe

Trojan.VB.Refpron.1 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
DrWebTrojan.VbCrypt.68
ClamAVWin.Trojan.Agent-6867325-0
CAT-QuickHealVirTool.Vbinder.Gen
ALYacGen:Trojan.VB.Refpron.1
CylanceUnsafe
ZillyaTrojan.Agent.Win32.74048
SangforTrojan.Win32.Save.a
AlibabaWorm:Win32/Vbinder.a8942850
K7GWTrojan ( 00565a481 )
K7AntiVirusTrojan ( 00565a481 )
CyrenW32/VB.AP.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.ALQ
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 99)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Trojan.VB.Refpron.1
NANO-AntivirusTrojan.Win32.Agent.dzdjuf
ViRobotTrojan.Win32.S.Agent.10752
MicroWorld-eScanGen:Trojan.VB.Refpron.1
TencentWin32.Worm.Vbna.Ammk
Ad-AwareGen:Trojan.VB.Refpron.1
SophosML/PE-A + Mal/VBCheMan-C
ComodoTrojWare.Win32.Agent.ddipe@1pwh8p
BitDefenderThetaGen:NN.ZevbaF.34170.amKfaKqYnWC
VIPREVirtool.Win32.Vbinject.1 (v)
TrendMicroTROJ_AGENT.AXRM
McAfee-GW-EditionGeneric VB.z
FireEyeGeneric.mg.7fb2ec1d7768db0b
EmsisoftGen:Trojan.VB.Refpron.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Refroso.alcu
WebrootTrojan.Dropper
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.5
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Trojan.VB.Refpron.1
AhnLab-V3Trojan/Win32.VBKrypt.R27644
McAfeeArtemis!7FB2EC1D7768
MAXmalware (ai score=100)
VBA32Malware-Cryptor.VB.gen.1
PandaGeneric Malware
TrendMicro-HouseCallTROJ_AGENT.AXRM
YandexTrojan.GenAsa!zAqBeAr8EH8
IkarusTrojan-Dropper.Win32.VB
MaxSecureTrojan.Malware.864183.susgen
FortinetW32/Refroso.BLC!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.VB.Refpron.1?

Trojan.VB.Refpron.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment