Malware

What is “VirTool:Win32/VBInject.AGW”?

Malware Removal

The VirTool:Win32/VBInject.AGW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.AGW virus can do?

  • Executable code extraction
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:Win32/VBInject.AGW?


File Info:

crc32: 3FC643A4
md5: 2b5aa4058dc90be599879439514308e0
name: 2B5AA4058DC90BE599879439514308E0.mlw
sha1: 9e7508b7545e696f44b8f46588f612e5e01391e4
sha256: dc2acd5e532375313e23213236a19f7ce4264bb66ec7baa39e31013d304122d5
sha512: 1d49f4d345364c9b7752c11603a9a00d2cf9da5beb8d1ee3f062ea94da7435aa420e360852abe76e46e0793902b7645f4e309f4c530d436dff86549280734d94
ssdeep: 768:xIDvv40bQFMe5xX4qBcwa+373Qc9pgmvH8SH2sJ560aiV8PimrTevv:30Q9rX4qBcwag7t2z0aiV8amrT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Romes
FileVersion: 3.07.0016
CompanyName: flasH
LegalTrademarks: ariation in placental morphology and refers a placenta separated
Comments: ariation in placental morphology and refers a placenta separated
ProductName: BoperJokas
ProductVersion: 3.07.0016
FileDescription: ariation in placental morphology and refers a placenta separated
OriginalFilename: Romes.exe

VirTool:Win32/VBInject.AGW also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.31297399
FireEyeGeneric.mg.2b5aa4058dc90be5
CAT-QuickHealTrojan.VBCrypt.MF.136
Qihoo-360Win32/Trojan.Ransom.eec
McAfeeTrojan-FJJV!2B5AA4058DC9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Shade.j!c
SangforMalware
K7AntiVirusTrojan ( 00512ddb1 )
BitDefenderTrojan.GenericKD.31297399
K7GWTrojan ( 00512ddb1 )
Cybereasonmalicious.58dc90
BitDefenderThetaGen:NN.ZevbaF.34804.hm0@a0Bpys
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DIUW
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Mansabo-6611665-0
KasperskyTrojan-Ransom.Win32.Shade.lhr
AlibabaRansom:Win32/Shade.363ef25a
NANO-AntivirusTrojan.Win32.Shade.ejshaa
RisingRansom.Shade!8.12CC (TFE:3:rc0CzUCvwLS)
Ad-AwareTrojan.GenericKD.31297399
SophosMal/Generic-S
ComodoMalware@#3a954oq2ba0tr
F-SecureHeuristic.HEUR/AGEN.1123157
DrWebTrojan.DownLoader22.63827
ZillyaTrojan.Injector.Win32.590651
TrendMicroTROJ_VBINJECT_HD200444.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
EmsisoftTrojan.GenericKD.31297399 (B)
IkarusTrojan.Win32.Injector
JiangminTrojan.Shade.dm
AviraHEUR/AGEN.1123157
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Shade
MicrosoftVirTool:Win32/VBInject.AGW
ArcabitTrojan.Generic.D1DD8F77
AhnLab-V3Trojan/Win32.Androm.C1709478
ZoneAlarmTrojan-Ransom.Win32.Shade.lhr
GDataWin32.Trojan-Spy.BrickTot.A
CynetMalicious (score: 85)
VBA32Hoax.Shade
ALYacTrojan.GenericKD.31297399
MalwarebytesTrojan.Injector
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_VBINJECT_HD200444.UVPM
TencentMalware.Win32.Gencirc.10ba6759
YandexTrojan.GenAsa!grxS6JsVJoY
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.DIUW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove VirTool:Win32/VBInject.AGW?

VirTool:Win32/VBInject.AGW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment