Malware

Should I remove “Win32/Codbot_AGen.A”?

Malware Removal

The Win32/Codbot_AGen.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Codbot_AGen.A virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Win32/Codbot_AGen.A?


File Info:

name: 1CD032712D8EC2EA4DDC.mlw
path: /opt/CAPEv2/storage/binaries/94cecdfb266ec77a3dc95a8f46bd767da953638ad86838833fd510ba821f7cc0
crc32: 8776A636
md5: 1cd032712d8ec2ea4ddce28f575d9df1
sha1: a86ef2ff0bce953dfd49611903f1beff66c700bf
sha256: 94cecdfb266ec77a3dc95a8f46bd767da953638ad86838833fd510ba821f7cc0
sha512: c7f9951763cb43f48dc6017663f735b765ead2d30565079e1e0b4c2737bc763bce7f4135c4fee1c25aae18c3cacb89a2aa396fd9b22f9883a650eeb26373221e
ssdeep: 192:YE44up0RkyaVWE44up0RkyaVYJEGKziXFnmnG88DKbTur370hdskRaez4guOaikq:Y9lckBVW9lckBVYoziXFwbRbw370A+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2E23B07B70089B3D42B9139727297D5D4E9BE312749E6C3A6B3776E58392E0093C70D
sha3_384: 9829a418fdfd4095ed7daafe8a390e6db39c0f4d715b9fb47de3c39e280e37bb377f72a1659e63d6b82bf3ed047f1a58
ep_bytes: 558bec81ec540200008d85e8fdffff68
timestamp: 2052-03-12 18:03:05

Version Info:

0: [No Data]

Win32/Codbot_AGen.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vtflooder.mmvI
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Lazy.348174
ClamAVWin.Malware.Lazy-10004133-0
FireEyeGeneric.mg.1cd032712d8ec2ea
CAT-QuickHealTrojan.Vflooder.S3863
ALYacGen:Variant.Lazy.348174
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Vtflooder.d4d9917a
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.f0bce9
BitDefenderThetaGen:NN.ZexaF.36722.cqY@a0WNttm
CyrenW32/Flooder.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Codbot_AGen.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Vtflooder.gen
BitDefenderGen:Variant.Lazy.348174
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Vtflooder.Ekjl
SophosMal/Generic-S
BaiduWin32.Trojan.Flooder.a
F-SecureTrojan.TR/Redcap.mmfso
VIPREGen:Variant.Lazy.348174
TrendMicroTROJ_GEN.R03BC0XFP23
McAfee-GW-EditionBehavesLike.Win32.Generic.nz
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Lazy.348174 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Lazy.348174
JiangminTrojan/Vtflooder.a
AviraTR/Redcap.mmfso
MAXmalware (ai score=89)
Antiy-AVLVirus/Win32.Expiro.ropf
ArcabitTrojan.Lazy.D5500E
ZoneAlarmHEUR:Trojan.Win32.Vtflooder.gen
MicrosoftTrojan:Win32/Vflooder.DS!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R583283
McAfeeArtemis!1CD032712D8E
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0XFP23
RisingTrojan.Vflooder!1.A165 (CLASSIC)
IkarusTrojan.Win32.Codbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Wacatac.B!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Codbot_AGen.A?

Win32/Codbot_AGen.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment