Malware

Win32/VBClone_AGen.B removal

Malware Removal

The Win32/VBClone_AGen.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VBClone_AGen.B virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/VBClone_AGen.B?


File Info:

name: ED27F6B13B220E91D522.mlw
path: /opt/CAPEv2/storage/binaries/32e7b70eabca5269cd616e768229492dc03d89be3c98f57ac8c64583096019f7
crc32: 3ADD119D
md5: ed27f6b13b220e91d522c36034e3b25e
sha1: 04ddb9c178b3b6ddf08fc75a884d57a3ec843e87
sha256: 32e7b70eabca5269cd616e768229492dc03d89be3c98f57ac8c64583096019f7
sha512: 780b56f125f284505e5f462aa16d189e346e4e819e6825b59e311b1961f4f6a571d6a0a2ad9f0c90395ba6e31c908cd8b13102d1f351ebcbbf6a8c0e6017fc77
ssdeep: 96:eKMN0evWZ0Ea8piH27vW6DQJsYU06bPqw55xIzzfhu:6P81ywksZ7DqwbWzfE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A104D5271B66DCB7D6C0D37446C4CBA5A6311402A3974E076E0E0D79B8B2B920CD6B0C
sha3_384: b1dacc42d0a3d766797e6f03e0d901fbf613a72db58f3e928f136ab23e8c290fa827aaf0935131558d7b269da5900100
ep_bytes: 68c0914200e8f0ffffff000000000000
timestamp: 2019-01-12 12:27:37

Version Info:

0: [No Data]

Win32/VBClone_AGen.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.tpHb
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.137693
FireEyeGeneric.mg.ed27f6b13b220e91
McAfeeGenericRXHD-KE!ED27F6B13B22
Cylanceunsafe
ZillyaTrojan.GenKryptik.Win32.205544
SangforDropper.Win32.Wacatac.V97o
K7AntiVirusP2PWorm ( 005499db1 )
AlibabaTrojan:Win32/Muldrop.329
K7GWP2PWorm ( 005499db1 )
Cybereasonmalicious.178b3b
VirITTrojan.Win32.VBUCornT.DRP
CyrenW32/Barys.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VBClone_AGen.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VB.dosb
BitDefenderGen:Variant.Fragtor.137693
NANO-AntivirusTrojan.Win32.VB.jxbiyy
AvastWin32:VB-AJKU [Trj]
TencentTrojan.Win32.VB.kh
TACHYONTrojan/W32.Agent.188416.BYJ
EmsisoftGen:Variant.Fragtor.137693 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop17.61497
VIPREGen:Variant.Fragtor.137693
TrendMicroTROJ_GEN.R002C0PFG23
McAfee-GW-EditionGenericRXHD-KE!ED27F6B13B22
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Fragtor.137693
JiangminTrojan.VB.aqek
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.VBClone
ArcabitTrojan.Fragtor.D219DD
ZoneAlarmTrojan.Win32.VB.dosb
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R589193
BitDefenderThetaGen:NN.ZevbaF.36662.lmW@aOWoCKl
ALYacGen:Variant.Fragtor.137693
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0PFG23
RisingTrojan.Generic@AI.100 (RDML:OCRckEQl+tRmdQhPR1NQMg)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Barys.AU!tr
AVGWin32:VB-AJKU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/VBClone_AGen.B?

Win32/VBClone_AGen.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment