Malware

Win32/VB_AGen.FI malicious file

Malware Removal

The Win32/VB_AGen.FI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB_AGen.FI virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/VB_AGen.FI?


File Info:

name: 241D9E1CAC065CEC754C.mlw
path: /opt/CAPEv2/storage/binaries/4e3a9e962cbf467bcd3004aa91e6fd9c1ceba087212457791e231375138f7ba4
crc32: 3024C089
md5: 241d9e1cac065cec754c8d8efef87e7a
sha1: efeea8e55a9b703d8e94795b470d6775f6c66d8c
sha256: 4e3a9e962cbf467bcd3004aa91e6fd9c1ceba087212457791e231375138f7ba4
sha512: 0ec1b5cf15c613592b03803a85c06e058261ae1f703641402e1583f796a7a207ba9c7569f545072de85ce2db6cf9e3e6ce5322c56deffb86096502e389d286b3
ssdeep: 12288:xZ45I8jWtJ8OgL27rd69bk5NCgGhSFB79gYhLIf6EQ9EYcw1F:xZ4kt0Kd6F6CNzYhUiEWEYcw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T112E412997F140498E51681F69CB7875D3A23BD7B13415A03392F7E8B4A7630A7F82A0F
sha3_384: 48e94b53a4ba60853067b349bced0b96a692864615472c5b34e7968b2db2cb597aa4084ec588cdb89e6ace3ffed459de
ep_bytes: c745fc78000000c78568ffffff78b041
timestamp: 2013-04-01 07:08:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: TJprojMain
OriginalFilename: TJprojMain.exe

Win32/VB_AGen.FI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.leZI
tehtrisGeneric.Malware
DrWebWin32.HLLP.Swisyn
FireEyeGeneric.mg.241d9e1cac065cec
McAfeeArtemis!241D9E1CAC06
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
AlibabaWorm:Win32/Mofksys.384
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaE.36318.Py0@au0OtNei
CyrenW32/VB.VC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VB_AGen.FI
APEXMalicious
ClamAVWin.Ransomware.Cryptor-9845758-0
KasperskyUDS:Trojan.Win32.Picsys
AvastWin32:TrojanX-gen [Trj]
SophosML/PE-A
BaiduWin32.Worm.VB.b
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Mofksys.1YE4CA
GoogleDetected
Antiy-AVLTrojan[Dropper]/Win32.Convagent
ZoneAlarmUDS:Trojan.Win32.Picsys
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RealProtect-LS.R568738
Cylanceunsafe
PandaTrj/Chgt.AD
ZonerTrojan.Win32.88925
RisingTrojan.Agent!1.6A70 (CLASSIC)
IkarusTrojan.Win32.VB
MaxSecureVirus.W32.Agent.xjgj
FortinetW32/VB_AGen.FI!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.55a9b7
DeepInstinctMALICIOUS

How to remove Win32/VB_AGen.FI?

Win32/VB_AGen.FI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment