Trojan

Trojan.Win32.Agent.vefb removal guide

Malware Removal

The Trojan.Win32.Agent.vefb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.vefb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Win32.Agent.vefb?


File Info:

name: 0735A21262334EB14B41.mlw
path: /opt/CAPEv2/storage/binaries/367ef1c3bfaf5c610b4839ec4810b4d0f5dfbccf1913c08892cad44c05cff5ac
crc32: 2C2889F9
md5: 0735a21262334eb14b4193e21959c073
sha1: 6e847aa84863a48eda2c389b85ef87280a5da610
sha256: 367ef1c3bfaf5c610b4839ec4810b4d0f5dfbccf1913c08892cad44c05cff5ac
sha512: a26170e179501a478b8d0c341d2363fdd30a237e3c629f66064dd5e2daa04df72dcef9a235bdcf9096533335f5a429699b900fd45032f1bbb71e665d970e4590
ssdeep: 3072:e4MP4vLk/HJ3y4CpCfCGCCOCwC9CvCFCfCLCvCUCLC2FInROUSRSGSuSQSmSNS4u:iP4wJ3yGFInRO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C81454FB24836D28C51D7C73137EDAA125A379C456CB508F23B32B9B3815D60CC769AA
sha3_384: d9be2d112d4687aed1c044c5319384a0ca1b6576f180d37e9a586a4f9829d916be6740a71593fc83e6768245edb125b4
ep_bytes: 68cc124000e8f0ffffff000050000000
timestamp: 2010-07-28 06:05:31

Version Info:

Translation: 0x0409 0x04b0
ProductName: ufpExTYR
FileVersion: 9.68
ProductVersion: 9.68
InternalName: ufpExTYR
OriginalFilename: ufpExTYR.exe

Trojan.Win32.Agent.vefb also known as:

BkavW32.AIDetectMalware
AVGWin32:Sality-GW [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.71823
FireEyeTrojan.GenericKDZ.71823
CAT-QuickHealTrojan.Beebone.D
ALYacTrojan.GenericKDZ.71823
Cylanceunsafe
VIPRETrojan.GenericKDZ.71823
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 00568eb91 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 00568eb91 )
Cybereasonmalicious.262334
BaiduWin32.Trojan.VB.a
VirITTrojan.Win32.Scar.LM
CyrenW32/Vobfus.I.gen!Eldorado
SymantecW32.Changeup.C
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.RU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Vobfus-9806879-0
KasperskyTrojan.Win32.Agent.vefb
BitDefenderTrojan.GenericKDZ.71823
NANO-AntivirusTrojan.Win32.Crypt.ddyvq
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Alg]
AvastWin32:Sality-GW [Trj]
TencentTrojan.Win32.Vbcode.a
EmsisoftTrojan.GenericKDZ.71823 (B)
F-SecureTrojan.TR/Poly.Agent.C
DrWebTrojan.Siggen5.23153
ZillyaTrojan.AgentGen.Win32.72
TrendMicroMal_VBNA-3
McAfee-GW-EditionBehavesLike.Win32.Vobfus.dt
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.71823
JiangminTrojan/Generic.atgeb
AviraTR/Poly.Agent.C
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Agent.vefb
XcitiumTrojWare.Win32.Downloader.VB.C@22k4yp
ArcabitTrojan.Generic.D1188F
ViRobotWorm.Win32.VB.131072.C
ZoneAlarmTrojan.Win32.Agent.vefb
MicrosoftWorm:Win32/Vobfus.AC
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R3761
Acronissuspicious
McAfeeVobfus-FCSW!0735A2126233
TACHYONTrojan/W32.Genome.204800.M
VBA32TScope.Trojan.VB
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_VBNA-3
RisingWorm.Win32.Undef.ow (CLASSIC)
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Agent.vefb
FortinetW32/VBNA.D!tr
BitDefenderThetaAI:Packer.13AD5B1F20
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Agent.vefb?

Trojan.Win32.Agent.vefb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment