Trojan

About “Trojan:Win32/VBClone!pz” infection

Malware Removal

The Trojan:Win32/VBClone!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/VBClone!pz virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/VBClone!pz?


File Info:

name: 08C2E409B09694489A2F.mlw
path: /opt/CAPEv2/storage/binaries/bc1bed725edaaf07db5399043d40c4377ec618d11a63718e8978ba64b4f9949a
crc32: AD716C7F
md5: 08c2e409b09694489a2fc1606d3f002e
sha1: 9c3caae1a06c2fe28d4c4c748dc3ebdb4254ea33
sha256: bc1bed725edaaf07db5399043d40c4377ec618d11a63718e8978ba64b4f9949a
sha512: f431af04eeef5ca04e1f95b4e08b50652201a32267137ffa55471d31f47c042e5fbb3344b50d6d0a6077c023fc41ec94231220518c8eb7f637027dbfa0f8e13a
ssdeep: 3072:4MdTo9hwBPAQkbTBDd7rW88b6ESorEeHTCRFxdvWmW2lVvMv:4MloOYnbZd/W88Tz6U2lVvM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B1148F619970BB16E915497817A06BFA001D3C2F47E9030DBCADDE5F3353DAA34AF942
sha3_384: c9534c4e79e34729e8b6fce98ce8d7583230af6110c98550bc8af1529249fefbbc88ae488d529c473fc33a9cddf19639
ep_bytes: 68c0914200e8f0ffffff000000000000
timestamp: 2019-01-12 12:27:37

Version Info:

0: [No Data]

Trojan:Win32/VBClone!pz also known as:

BkavW32.AIDetectMalware
DrWebTrojan.MulDrop17.61497
MicroWorld-eScanGen:Variant.Barys.337384
SkyhighBehavesLike.Win32.Generic.cc
McAfeeGenericRXGW-RL!08C2E409B096
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.VBGen.Win32.1
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005690671 )
K7AntiVirusTrojan ( 005690671 )
BitDefenderThetaAI:Packer.9E2EBB921F
VirITTrojan.Win32.Banker1.BRRU
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VBClone.D
APEXMalicious
ClamAVWin.Malware.Generickdz-10004857-0
KasperskyTrojan.Win32.VB.dosb
BitDefenderGen:Variant.Barys.337384
NANO-AntivirusTrojan.Win32.VB.fmvqeg
SUPERAntiSpywareTrojan.Agent/Gen-Strictor
AvastWin32:VB-AJKU [Trj]
TencentTrojan.Win32.VB.kh
EmsisoftGen:Variant.Barys.337384 (B)
GoogleDetected
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Barys.337384
TrendMicroTrojan.Win32.FAREIT.SMYXEA3
FireEyeGeneric.mg.08c2e409b0969448
SophosMal/VB-AQT
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.337384
JiangminTrojan.VB.aqyg
VaristW32/VB.QG.gen!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.VP2.a
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.VBClone.B@88ji29
ArcabitTrojan.Barys.D525E8
ZoneAlarmTrojan.Win32.VB.dosb
MicrosoftTrojan:Win32/VBClone!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R436298
Acronissuspicious
ALYacGen:Variant.Barys.337384
VBA32SScope.Trojan.VB
Cylanceunsafe
RisingTrojan.VBClone!1.E032 (CLASSIC)
IkarusTrojan.Crypt
MaxSecureVirus.W32.GenericML.xnet
FortinetW32/VBClone.D!tr
AVGWin32:VB-AJKU [Trj]
Cybereasonmalicious.1a06c2
DeepInstinctMALICIOUS

How to remove Trojan:Win32/VBClone!pz?

Trojan:Win32/VBClone!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment