Trojan

Trojan:Win32/VB.AGL removal instruction

Malware Removal

The Trojan:Win32/VB.AGL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VB.AGL virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/VB.AGL?


File Info:

name: 5D9C7EDBC463BE2B737A.mlw
path: /opt/CAPEv2/storage/binaries/1f4b326051cf23752026559ee7bdace5909f490899a32634adbeafaf5fa6b23e
crc32: 961695D9
md5: 5d9c7edbc463be2b737a8385b5f10a59
sha1: 56aeb9ae4ca53663075932f5ab8857acc3bcd655
sha256: 1f4b326051cf23752026559ee7bdace5909f490899a32634adbeafaf5fa6b23e
sha512: 7039ee1fc417f39fab6a5f8021f17f97dded523f5ac835663fe763be849bded56b0c4e0194db5b29ea8eb4c489f9883bc16e6295faac2040ff1a84ad7cd27311
ssdeep: 3072:p/FjDQOYonXeDYsiqbRw13Yezgn1ejMXQq/SI7txLSyAqGEkNfn:ptDQoXeDYsiqbRw13Yezgn1ejMXQq/St
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D04405FF58D2191FA41A43D3AB6662F1CA45D3A4681DC0AEB046B4639B10F3F0F962F
sha3_384: d7972a91c9a3ba8867fc7d8cfe9d8f18b3cff24622dc3b040e04ff34d622fbcfd21db696d9626da62ecee2439ac87664
ep_bytes: 683c304000e8f0ffffff000000000000
timestamp: 2011-05-26 00:19:56

Version Info:

0: [No Data]

Trojan:Win32/VB.AGL also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.5d9c7edbc463be2b
SkyhighBehavesLike.Win32.PWSZbot.cm
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.e4ca53
SymantecTrojan.Gen.MBT
APEXMalicious
ClamAVWin.Downloader.Ockessm-9824679-0
KasperskyTrojan.Win32.Vilsel.bbbz
AlibabaTrojan:Win32/Vilsel.4e598a87
ViRobotTrojan.Win32.A.Vilsel.287744
SophosMal/VB-S
DrWebBackDoor.Generic.3107
ZillyaTrojan.Vilsel.Win32.25334
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vilsel.aexn
GoogleDetected
VaristW32/Agent.CC.gen!Eldorado
Antiy-AVLTrojan/Win32.Vilsel
Kingsoftmalware.kb.b.956
MicrosoftTrojan:Win32/VB.AGL
XcitiumMalware@#1je3ad1n03mag
ZoneAlarmTrojan.Win32.Vilsel.bbbz
CynetMalicious (score: 100)
McAfeeArtemis!5D9C7EDBC463
DeepInstinctMALICIOUS
VBA32suspected of Trojan-Spy.xBank.8
PandaTrj/CI.A
RisingTrojan.VB!8.B20 (TFE:3:OeYp8v4ZMiT)
YandexTrojan.Vilsel!HgkbQ6oZRzQ
IkarusTrojan.Win32.Vilsel
MaxSecureTrojan.Malware.2888226.susgen
FortinetW32/VB.OBS!tr
AVGWin32:Bancos-BSJ [Trj]
AvastWin32:Bancos-BSJ [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/VB.AGL?

Trojan:Win32/VB.AGL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment