Malware

What is “Win32/VBClone_AGen.C”?

Malware Removal

The Win32/VBClone_AGen.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VBClone_AGen.C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/VBClone_AGen.C?


File Info:

name: D81817EC4C79897C1160.mlw
path: /opt/CAPEv2/storage/binaries/c88134d23f868725000bcd88c1f897cd1e1f0877e2c4acd51dda74106da1e326
crc32: DF40EA93
md5: d81817ec4c79897c116099cc3b41945e
sha1: d2c392928138ce36b4d811e73f29f267a2b3df62
sha256: c88134d23f868725000bcd88c1f897cd1e1f0877e2c4acd51dda74106da1e326
sha512: bc7df96e90510c10b3a5133d50c91e5aa1028ddd15f9896b7d1778472872b05a488ec806a543507758e62841304122b1c38e83861d33e4a91801bbf16c266632
ssdeep: 3072:iRwd6kcHbYHe6dD3tWi98ttM3lvnq7viuh:iRwAHR2D318/M3lPq7viu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127048F628970BB13E951093417E06BFB801D3D2F4BE506097CAEDA5F3763D9A349FA42
sha3_384: b342732e869a89787071ba1181e57f669c18d512540d5bf0f9eb2a53cc17672389418d7ff9672dcb8ae2472ae7621b24
ep_bytes: 68c0914200e8f0ffffffcd0000000000
timestamp: 2019-04-26 10:28:09

Version Info:

0: [No Data]

Win32/VBClone_AGen.C also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.MulDrop17.61497
MicroWorld-eScanGen:Variant.Midie.74955
ClamAVWin.Malware.Midie-6847893-0
SkyhighBehavesLike.Win32.Generic.ct
McAfeeGenericRXHC-SS!D81817EC4C79
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 00581a9e1 )
K7GWP2PWorm ( 00581a9e1 )
Cybereasonmalicious.28138c
ArcabitTrojan.Midie.D124CB
BitDefenderThetaAI:Packer.6AD2523D1F
VirITTrojan.Win32.VBUCornT.DRP
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VBClone_AGen.C
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.pef
BitDefenderGen:Variant.Midie.74955
NANO-AntivirusTrojan.Win32.VBClone.jtuopc
AvastWin32:VB-AJKU [Trj]
EmsisoftGen:Variant.Midie.74955 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPREGen:Variant.Midie.74955
SophosMal/Generic-S
IkarusTrojan.Crypt
JiangminTrojan.VB.aqyg
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLGrayWare/Win32.VP2.a
Kingsoftmalware.kb.a.999
MicrosoftTrojanDropper:Win32/Muldrop.V!MTB
ZoneAlarmHEUR:Trojan.Win32.Agent.pef
GDataWin32.Trojan.VBClone.C
VaristW32/VB_Troj.J.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R603325
Acronissuspicious
VBA32SScope.Trojan.VB
ALYacGen:Variant.Midie.74955
TACHYONTrojan/W32.VB-Agent.188475.E
Cylanceunsafe
RisingTrojan.VBClone!1.E032 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/VBClone.D!tr
AVGWin32:VB-AJKU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/VBClone_AGen.C?

Win32/VBClone_AGen.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment