Malware

Win32/Agent.VIM removal tips

Malware Removal

The Win32/Agent.VIM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.VIM virus can do?

  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Win32/Agent.VIM?


File Info:

name: 7B0CB9897870F3F7811C.mlw
path: /opt/CAPEv2/storage/binaries/7530669c8da8ae0fb9d7df3571298955abdd19a670b719a5413e637d21aef278
crc32: 0ACDD74A
md5: 7b0cb9897870f3f7811cb61766a952d7
sha1: 00728053cf100f6c752c6b12613b5324a5b8df84
sha256: 7530669c8da8ae0fb9d7df3571298955abdd19a670b719a5413e637d21aef278
sha512: 9ce3d3217cd8c795c35373dbb1b171025d6c568461b64b0bf74fe0dbb49b9934f7da50ac798f9e0a6cffd137bebcf9dcce99d8959259c6208375f637e8ada41a
ssdeep: 6144:RDuTZ0DXq/krthWvgpdehyMlHo6UV1htAOvrr6Q:RDuTZl/krLWvgpb6Yhtd6Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A147C2174D2C432D572153209E8DBB59A3DB9600BA69DFF67D44F3E4F302C2E631A6A
sha3_384: e03361276c7e07f35d664a2c1fdecf8be31df5625dd26d969aac7b14b2335f4ef77fcc979b28fbcee0305e3e38764a88
ep_bytes: e89c050000e97afeffff8b4df464890d
timestamp: 2023-06-13 02:19:31

Version Info:

0: [No Data]

Win32/Agent.VIM also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.GenericML.4!c
MicroWorld-eScanTrojan.GenericKD.67506831
FireEyeGeneric.mg.7b0cb9897870f3f7
ALYacTrojan.GenericKD.67506831
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a8f521 )
K7GWTrojan ( 005a8f521 )
ArcabitTrojan.Generic.D406128F
BitDefenderThetaGen:NN.ZexaF.36318.muW@aKmT4rfi
CyrenW32/Agent.GKO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.VIM
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderTrojan.GenericKD.67506831
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Agent.Nqil
EmsisoftTrojan.GenericKD.67506831 (B)
F-SecureTrojan.TR/Agent.ubefr
VIPRETrojan.GenericKD.67506831
TrendMicroTROJ_GEN.R023C0XFF23
McAfee-GW-EditionBehavesLike.Win32.BadFile.dh
SophosMal/Generic-S
AviraTR/Agent.ubefr
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
GDataTrojan.GenericKD.67506831
GoogleDetected
AhnLab-V3Backdoor/Win32.RL_Keylogger.R361087
McAfeeArtemis!7B0CB9897870
MAXmalware (ai score=82)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R023C0XFF23
RisingTrojan.Agent!8.B1E (TFE:5:XKnfUNcCFIV)
IkarusTrojan.Win32.HackTool
MaxSecureTrojan.Malware.185628869.susgen
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent.VIM?

Win32/Agent.VIM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment