Malware

About “Win32/PSW.VB.NFA” infection

Malware Removal

The Win32/PSW.VB.NFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.VB.NFA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/PSW.VB.NFA?


File Info:

name: A08C51C6522A574662EF.mlw
path: /opt/CAPEv2/storage/binaries/c0b4541a67b962cd289594b498492f0c3fb641756fafadc167a1a7d189a97317
crc32: FFA9B0DE
md5: a08c51c6522a574662efa4a4007a9cbf
sha1: 23ff21fc1ec859efc6cb52c3d34c15e4358552e9
sha256: c0b4541a67b962cd289594b498492f0c3fb641756fafadc167a1a7d189a97317
sha512: 9986c130a3611bcb2ab202688fe9f1e9adb7f429c52a27c513515d5f1a518ec11cc2a703f6e2b61c9b828b8c6566ce2e511e3a49f7a2415a96f356b8eb20a226
ssdeep: 1536:Weox7d5E/qyC31lf5TY79I+twcF98jzRtCXDdP1asE2P46MjWUQnXPu:WeoxXEo31lf5kwGZNasE2Q6sQn/u
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D3A30822F6942025F1674AB13E78956A69297C360901EC1FF7819B4D38706D3FAF171F
sha3_384: 951be89dd81153cdee77685fed4292bf3a6ab8939cc386e786921410b9fd80ae971f0db1e0b43027d24d87799944b259
ep_bytes: 68e01f4000e8f0ffffff000000000000
timestamp: 2009-04-25 09:18:23

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Microsoft Corporation
FileDescription: Generic Host Process for Win32 Services
ProductName: Flash
FileVersion: 1.03.0229
ProductVersion: 1.03.0229
InternalName: wrk32
OriginalFilename: wrk32.exe

Win32/PSW.VB.NFA also known as:

LionicTrojan.Multi.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Jaiko.5145
FireEyeGeneric.mg.a08c51c6522a5746
McAfeeGeneric Malware.mt
CylanceUnsafe
VIPREGen:Variant.Jaiko.5145
SangforSuspicious.Win32.Save.vb
K7AntiVirusPassword-Stealer ( 0005a7911 )
AlibabaTrojanPSW:Win32/Reconyc.2ce18d7f
K7GWPassword-Stealer ( 0005a7911 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.VB.NFA
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Reconyc.arf
BitDefenderGen:Variant.Jaiko.5145
NANO-AntivirusTrojan.Win32.Reconyc.cxnhaj
AvastWin32:Trojan-gen
TencentWin32.Trojan.Reconyc.Uylw
Ad-AwareGen:Variant.Jaiko.5145
EmsisoftGen:Variant.Jaiko.5145 (B)
ComodoMalware@#2nqr21dyho7si
DrWebTrojan.DownLoader11.40529
ZillyaTrojan.Reconyc.Win32.3045
McAfee-GW-EditionGeneric Malware.mt
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Jaiko.5145
JiangminTrojan/Reconyc.yr
AviraTR/Spy.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.330C
KingsoftWin32.Troj.Reconyc.a.(kcloud)
ArcabitTrojan.Jaiko.D1419
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Win-Trojan/MDA.140610.X1298
BitDefenderThetaAI:Packer.D302BFDB1F
ALYacGen:Variant.Jaiko.5145
VBA32Trojan.Reconyc
MalwarebytesRiskWare.SpySoft
RisingMalware.Undefined!8.C (TFE:5:ASioWwHVixD)
YandexTrojan.GenAsa!zwFh4ZVYK0s
IkarusBehavesLike
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Reconyc.ARF!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.6522a5
PandaGeneric Malware

How to remove Win32/PSW.VB.NFA?

Win32/PSW.VB.NFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment