Worm

Dropped:Win32.Worm.VB.NXJ (B) malicious file

Malware Removal

The Dropped:Win32.Worm.VB.NXJ (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Win32.Worm.VB.NXJ (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine Dropped:Win32.Worm.VB.NXJ (B)?


File Info:

name: AB50DEAE77F5A2258F2D.mlw
path: /opt/CAPEv2/storage/binaries/b4c287697fd83d0d7af5c124372c102e6caee83c233080b833070338441bf2e2
crc32: 69B50261
md5: ab50deae77f5a2258f2d14d3aa478020
sha1: 09f87e2747f3ea2555d20f9b4ed4699437f9e443
sha256: b4c287697fd83d0d7af5c124372c102e6caee83c233080b833070338441bf2e2
sha512: 02d3b992a44cc100be4c1b0422c969779c40ea32967f53dd50b8a976434782a11641c8342500136a87ea7184c0c66b62edf3a88f1db2e2e4b6227bf79d37ded7
ssdeep: 49152:4IA1tRaMMMMM2MMMMMpqC/NHCIA1tRaMMMMM2MMMMMpqC/NHW:4IItRaMMMMM2MMMMMp1/EIItRaMMMMMu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123A55A11BBE3A13AECA3163019B982309679BD215B35D3CF97817A5D6D71BD1AA30333
sha3_384: 0602b96655fe724015632c935eb82a9028505250c32e6919a9820ce604b72e4578aca6cd932ee18b375afa35900cec67
ep_bytes: 68184e4000e8eeffffff000000000000
timestamp: 2007-09-07 11:28:55

Version Info:

0: [No Data]

Dropped:Win32.Worm.VB.NXJ (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.tpDK
Elasticmalicious (moderate confidence)
MicroWorld-eScanDropped:Win32.Worm.VB.NXJ
FireEyeGeneric.mg.ab50deae77f5a225
CAT-QuickHealTrojan.VB.S692133
McAfeeGenericRXAB-MY!AB50DEAE77F5
CylanceUnsafe
ZillyaTrojan.VB.Win32.119028
Sangfor[MICROSOFT VISUAL BASIC 5.0]
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.1C8CE2EC1E
CyrenW32/Presenoker.B.gen!Eldorado
SymantecW32.Pajetbin
ESET-NOD32a variant of Win32/VB.QZU
BaiduWin32.Trojan.VB.t
TrendMicro-HouseCallTROJ_VB.BJR
ClamAVWin.Dropper.Pajetbin-7136153-0
KasperskyTrojan.Win32.Agent.qwiffa
BitDefenderDropped:Win32.Worm.VB.NXJ
NANO-AntivirusTrojan.Win32.VB.tole
CynetMalicious (score: 100)
AvastWin32:VB-FBX
TencentTrojan.Win32.Agent.bt
Ad-AwareDropped:Win32.Worm.VB.NXJ
SophosML/PE-A + Troj/VB-DYS
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebWin32.HLLP.Woner
VIPREDropped:Win32.Worm.VB.NXJ
TrendMicroTROJ_VB.BJR
Trapminemalicious.moderate.ml.score
EmsisoftDropped:Win32.Worm.VB.NXJ (B)
APEXMalicious
GDataWin32.Worm.Pajetbin.A
JiangminTrojan/VB.ckti
AviraTR/Agent.57344.1474
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.1F
ZoneAlarmTrojan-Spy.Win32.Zbot.wten
MicrosoftTrojan:Win32/Vindor.B
GoogleDetected
AhnLab-V3Trojan/Win32.Refroso.C22136
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacDropped:Win32.Worm.VB.NXJ
TACHYONBanker/W32.Banbra.Gen
MalwarebytesVB.Virus.FileInfector.DDS
IkarusVirus.Win32.VB.gp
RisingTrojan.KillAV!1.66BF (CLASSIC)
YandexTrojan.GenAsa!IPLOeyvnoUg
SentinelOneStatic AI – Malicious PE
FortinetW32/VB.PG
AVGWin32:VB-FBX
Cybereasonmalicious.e77f5a
PandaW32/VB.ABL

How to remove Dropped:Win32.Worm.VB.NXJ (B)?

Dropped:Win32.Worm.VB.NXJ (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment