Trojan

Trojan:Win32/VBClone removal instruction

Malware Removal

The Trojan:Win32/VBClone is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VBClone virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/VBClone?


File Info:

name: AC03598ED07A9526716E.mlw
path: /opt/CAPEv2/storage/binaries/13b48931867d7be431e144e4cfa7af5e3868e26b7b08d29feb6a4bf1f13b7e6a
crc32: 2A683AB9
md5: ac03598ed07a9526716e99aa554a9ccd
sha1: fe188fb2c5f868348be0244caddb1247313eaef2
sha256: 13b48931867d7be431e144e4cfa7af5e3868e26b7b08d29feb6a4bf1f13b7e6a
sha512: 9973583092af17957b09716f99b20aa43cf61b359ff44ce712c5ab5b16db924aacabc3c3298a7a73a1334fe421fb1c3db71e02bd8741becf21c3ce47387daa89
ssdeep: 768:/dCueuDdmpMQXfSftnihuYG1CWJVBd5Sfs:/YwDdmpMQPSftihuYGMWVdH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E3385A59E19CC2ACA1C15B55463C7B2084E1CB8D8D80D51DFEDECE435B48EF25EC2AB
sha3_384: de290ed923ec6bd216d5d18234646b96283244d1456ea7fe2275eae5542f63d4b7f2aa52f78ff0f02182a80ab1dce3a8
ep_bytes: 680c504000e8f0ffffff000000000000
timestamp: 2012-06-24 06:09:09

Version Info:

0: [No Data]

Trojan:Win32/VBClone also known as:

BkavW32.FamVT.VBCloneAATTc.Worm
LionicTrojan.Win32.VB.tnqI
MicroWorld-eScanTrojan.Agent.VB.CAT
FireEyeGeneric.mg.ac03598ed07a9526
CAT-QuickHealTrojan.Cuvt.A3
McAfeeTrojan-FGAU!AC03598ED07A
MalwarebytesVBClone.Trojan.Agent.DDS
VIPRETrojan.Agent.VB.CAT
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 004c16291 )
AlibabaTrojan:Win32/VBClone.33a
K7GWP2PWorm ( 004bf10d1 )
Cybereasonmalicious.ed07a9
BaiduWin32.Adware.Kryptik.h
CyrenW32/S-a70b72ab!Eldorado
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32Win32/VBClone.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VB.cuvt
BitDefenderTrojan.Agent.VB.CAT
NANO-AntivirusTrojan.Win32.VB.fnrisw
SUPERAntiSpywareTrojan.Agent/Generic
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Vb.za
EmsisoftTrojan.Agent.VB.CAT (B)
F-SecureTrojan.TR/VB.Agent.dleuig
DrWebTrojan.VbCrypt.250
ZillyaTrojan.VBGen.Win32.2
TrendMicroTROJ_GEN.R002C0CEG23
McAfee-GW-EditionBehavesLike.Win32.VBObfus.qz
Trapminemalicious.high.ml.score
SophosMal/VB-APD
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.VBClone.A
JiangminTrojan/VB.czdk
AviraTR/VB.Agent.dleuig
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.VB.cuvt
XcitiumTrojWare.Win32.VBClone.CUV@5qbrk1
ArcabitTrojan.Agent.VB.CAT
ViRobotTrojan.Win32.Vbclone.Gen.A
ZoneAlarmTrojan.Win32.VB.cuvt
MicrosoftTrojan:Win32/VBClone
GoogleDetected
AhnLab-V3Unwanted/Win32.Agent.R233450
BitDefenderThetaGen:NN.ZevbaF.36196.dmX@aGwaI2p
ALYacTrojan.Agent.VB.CAT
TACHYONTrojan/W32.VB-Agent.53358
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0CEG23
RisingTrojan.Win32.VBClone.a (CLASSIC)
YandexTrojan.GenAsa!bGi81v33ZVw
IkarusTrojan.VB.Agent
FortinetW32/Generic.AC.1103!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/VBClone?

Trojan:Win32/VBClone removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment