Malware

W32/Clovis-A information

Malware Removal

The W32/Clovis-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Clovis-A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Operates on local firewall’s policies and settings

How to determine W32/Clovis-A?


File Info:

name: CB6F3B65777EB96DFD2E.mlw
path: /opt/CAPEv2/storage/binaries/be51fa46e7a2ea7b3f0dcd5e2a718686a1145f0676f8a14c585b014381918edd
crc32: 36A60C75
md5: cb6f3b65777eb96dfd2e96b31014800e
sha1: e79fa01bce4cb350d7bfc8ccb00af035a7734a3b
sha256: be51fa46e7a2ea7b3f0dcd5e2a718686a1145f0676f8a14c585b014381918edd
sha512: 4bad57da1f174397959e8ed556acddc51ae977486b06bb0bf08b4b38c93857544c62a608ba7f4eda92d65da4d46a27be2a27285843aa50b33fb096dbf4970a18
ssdeep: 768:EfZivXrVKpVhKvtxwYHwVFoeAQXmucwUyfVAThsf4vvvWTDoNMh:6ZqrVKprVuQXxfVAhNW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB730A5242C5443FD4304CFC2609177D975ABFBA2B903867F615FE6B39322B3AA0D4A6
sha3_384: 8fdfd7145d71b76bb88f99bc7eeb04e55bd311e150e3fd3c54008cfb17bd17afa4f83b21b5aa80ac981dff07a7912a9e
ep_bytes: 5589e56aff68e0644000685844400064
timestamp: 2000-12-26 01:24:45

Version Info:

0: [No Data]

W32/Clovis-A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.LolBot.lma9
AVGWin32:StartPage-APD [Trj]
DrWebTrojan.Siggen2.56716
MicroWorld-eScanTrojan.GenericKDZ.95048
FireEyeGeneric.mg.cb6f3b65777eb96d
CAT-QuickHealWorm.Duptwux.A4
SkyhighBehavesLike.Win32.Duptwux.lt
ALYacTrojan.GenericKDZ.95048
Cylanceunsafe
ZillyaTrojan.AgentGen.Win32.77
SangforTrojan.Win32.Save.a
AlibabaWorm:Win32/Ganelp.b318
Cybereasonmalicious.5777eb
BitDefenderThetaGen:NN.ZexaF.36802.eyY@aCeNYaii
VirITTrojan.Win32.Agent2.CJTM
SymantecW32.Griptolo
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.RTF
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Lolbot-6787741-0
KasperskyHEUR:Worm.Win32.Generic
BitDefenderTrojan.GenericKDZ.95048
NANO-AntivirusTrojan.Win32.LolBot.wjzgy
SUPERAntiSpywareTrojan.Agent/Gen-Duptwux
AvastWin32:StartPage-APD [Trj]
TencentTrojan.Win32.Agent.tol
EmsisoftTrojan.GenericKDZ.95048 (B)
F-SecureTrojan.TR/Agent.3533215
BaiduWin32.Trojan.Agent.ej
VIPRETrojan.GenericKDZ.95048
TrendMicroWORM_DUPTWU.SMIA
Trapminemalicious.moderate.ml.score
SophosW32/Clovis-A
IkarusBackdoor.Win32.LolBot
JiangminBackdoor/LolBot.jq
AviraTR/Agent.3533215
Antiy-AVLWorm/Win32.Ganelp
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Ganelp.E
GridinsoftTrojan.Win32.Agent.sa
XcitiumBackdoor.Win32.LolBot.GA@48x6oc
ArcabitTrojan.Generic.D17348
ZoneAlarmHEUR:Worm.Win32.Generic
GDataWin32.Worm.Ganelp.B
VaristW32/LolBot.A.gen!Eldorado
AhnLab-V3Backdoor/Win32.LolBot.C117938
Acronissuspicious
McAfeeGenericRXGH-XT!CB6F3B65777E
MAXmalware (ai score=81)
VBA32BScope.Worm.Juched
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallWORM_DUPTWU.SMIA
RisingTrojan.Win32.Fednu.dks (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.LolBot.gen
FortinetW32/Agent.RTK!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Lolbot.9fd58ef7

How to remove W32/Clovis-A?

W32/Clovis-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment