Malware

Should I remove “Win32/VBClone.J”?

Malware Removal

The Win32/VBClone.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VBClone.J virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/VBClone.J?


File Info:

name: 955B8F97D66846E52964.mlw
path: /opt/CAPEv2/storage/binaries/f5714c4f29bdedfecd85d0c396c3e4786e59853859c97d51e487e6c51f785933
crc32: A6D1611C
md5: 955b8f97d66846e529642936c08faae6
sha1: ffc05986f96b7b90711bf2224df768913acaa041
sha256: f5714c4f29bdedfecd85d0c396c3e4786e59853859c97d51e487e6c51f785933
sha512: ad8d6a8a17c9eead78f732a36abbd33f56213e0043325ccb383135b699f25be19d900003e35b55fbfb32bdbd766f4cd9b51c992237030ecb324b7c048d76ea79
ssdeep: 3072:T9DxajoY4vBCkHqsHJcOHibOISOoD6JsO0SlT5xIU5jJlnTOF2:T9Eo/PHqvOCbOImz4jJlnTOF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1550480628970BB16E915093517A46BEA401D3C2F4BE5030DBCADDE5F3353DAB34AF942
sha3_384: 15a31fa02cee26794be4273d72ba7300615835e01d358270f4ca1895d0bd84cc918c9be9f570cb89282b399b05ed9f99
ep_bytes: 68c0914200e8f0ffffffcd0000000000
timestamp: 2019-01-12 12:27:37

Version Info:

0: [No Data]

Win32/VBClone.J also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.tsbh
Elasticmalicious (high confidence)
ALYacTrojan.GenericKDZ.94039
VIPRETrojan.GenericKDZ.94039
CynetMalicious (score: 100)
K7AntiVirusP2PWorm ( 00581a9e1 )
K7GWP2PWorm ( 00581a9e1 )
Cybereasonmalicious.7d6684
VirITTrojan.Win32.Banker1.BRRU
tehtrisGeneric.Malware
ESET-NOD32Win32/VBClone.J
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKDZ.94039
AvastWin32:VB-AJKU [Trj]
RisingTrojan.VBClone!1.E032 (CLASSIC)
EmsisoftTrojan.GenericKDZ.94039 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.MulDrop17.61497
ZillyaTrojan.VB.Win32.830511
TrendMicroTROJ_GEN.R03BC0DLB22
FireEyeGeneric.mg.955b8f97d66846e5
SophosMal/VB-AQT
IkarusTrojan.Crypt
JiangminTrojan.VB.aqyg
Antiy-AVLGrayWare/Win32.VP2.a
ArcabitTrojan.Generic.D16F57
ZoneAlarmTrojan.Win32.VB.dosp
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R252862
BitDefenderThetaAI:Packer.C2A4C2A61D
MAXmalware (ai score=84)
VBA32SScope.Trojan.VB
PandaTrj/Genetic.gen
TencentTrojan.Win32.Wacatac.yaw
YandexTrojan.VB!txFqlQbgPDs
SentinelOneStatic AI – Malicious PE
FortinetW32/VBClone.D!tr
AVGWin32:VB-AJKU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/VBClone.J?

Win32/VBClone.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment