Malware

Should I remove “VBS/Agent.NMM”?

Malware Removal

The VBS/Agent.NMM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBS/Agent.NMM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • A script or command line contains a long continuous string indicative of obfuscation
  • Deletes executed files from disk
  • Attempts to execute suspicious powershell command arguments
  • Collects information to fingerprint the system
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine VBS/Agent.NMM?


File Info:

name: 2AD66DB33311E4CB39DF.mlw
path: /opt/CAPEv2/storage/binaries/fca1ceca0d9d9b8a746ab51dc5b64e9fa57af1478de24a98989b202872fcae5a
crc32: D70C8825
md5: 2ad66db33311e4cb39df7955c57ec353
sha1: 35236192f250b54c378b26361579f6092848ec1c
sha256: fca1ceca0d9d9b8a746ab51dc5b64e9fa57af1478de24a98989b202872fcae5a
sha512: f891b8177a7b3dd2cd662e11a927fdad4af5873d51cb2fef2db66bdee3dd2881cd112a3914668cc6403222ef3a5925f95159d4f180f3c5ba0966bccdfd22c9a0
ssdeep: 3072:48U2yJN5f661xRZbALxB1Ojdgx8GYz/LQxFPk:48U2qy6rRZb7jxGYzEPk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1C3AD04B7C681F3D4401B3058AE6376EB39FF256A71E29EC7966D1D2C20602F51AFB6
sha3_384: 61270b44c03fd4d12765818961935bc02570edafc809fed0377add02d1c6a61604927c20ffa03598c9199c5af136fcab
ep_bytes: e82f2b000050e83f3101000000000090
timestamp: 2007-05-05 05:40:22

Version Info:

0: [No Data]

VBS/Agent.NMM also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.65785612
FireEyeTrojan.GenericKD.65785612
ALYacTrojan.VBS.VDA
Cylanceunsafe
VIPRETrojan.GenericKD.65785612
SangforTrojan.Vbs.Agent.V62k
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Skeeyah.5fe624fa
K7GWTrojan ( 005136201 )
K7AntiVirusTrojan ( 005136201 )
CyrenW32/ABRisk.UMZC-1434
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32VBS/Agent.NMM
APEXMalicious
AvastOther:Malware-gen [Trj]
KasperskyUDS:Trojan.MSIL.Disfa
BitDefenderTrojan.GenericKD.65785612
NANO-AntivirusTrojan.Script.Vbs-heuristic.druvzi
TencentScript.Trojan-Downloader.Generic.Zfow
EmsisoftTrojan.GenericKD.65785612 (B)
DrWebTrojan.MulDrop21.34902
TrendMicroVBS_POWLOAD.GAC
McAfee-GW-EditionW97M/Downloader.rt
Trapminemalicious.high.ml.score
SophosVBS/Agent-AYZJ
Paloaltogeneric.ml
GDataTrojan.GenericKD.65785612
GoogleDetected
AviraWORM/VBS.Agent.davcp
ArcabitTrojan.Generic.D3EBCF0C
ViRobotTrojan.Win.Z.Vbs.129379
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C3009659
McAfeeArtemis!2AD66DB33311
MAXmalware (ai score=81)
VBA32BScope.TrojanDropper.Sysn
MalwarebytesTrojan.Dropper.SFXAI
TrendMicro-HouseCallVBS_POWLOAD.GAC
RisingMalware.FakeFolder/ICON!1.6ABB (CLASSIC)
IkarusWorm.VBS.Agent
MaxSecureTrojan.Malware.12129966.susgen
FortinetVBS/Agent.NMM!tr
AVGOther:Malware-gen [Trj]
Cybereasonmalicious.33311e
PandaTrj/CI.A

How to remove VBS/Agent.NMM?

VBS/Agent.NMM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment