Malware

Win32/PSW.VB.NKQ removal tips

Malware Removal

The Win32/PSW.VB.NKQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.VB.NKQ virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/PSW.VB.NKQ?


File Info:

crc32: FCF84D7B
md5: 41cd78f753883a02536adb9d91e2bdfa
name: 41CD78F753883A02536ADB9D91E2BDFA.mlw
sha1: 6f5f6d9b6e35b3a92ca3063e2a5f0cb009f100d2
sha256: 2cc2b8dc2a4fe9da3f90b11134fb057e19e3d59ffd18ced8e38d099d5cb0abdc
sha512: dba8e50d40b2865887e4fad8afc649d72e0e3c972ae81d0be9a89a075bfb80f0274dbca38bc8a11f788209d998b24347d95de8eb362bc9eff425d96b5d7955d0
ssdeep: 6144:qM9/abB49OzeiM6gtN/Wx1nOCcAZoey0sTF41O:J/SixjTnC5Zo30sTFg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: x41dx430x43ax440x443x442x43ax430!
FileVersion: 1.00
CompanyName: Melkosoft
ProductName: x41fx440x43ex435x43ax4421
ProductVersion: 1.00
OriginalFilename: x41dx430x43ax440x443x442x43ax430!.exe

Win32/PSW.VB.NKQ also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
CylanceUnsafe
ZillyaTrojan.VB.Win32.151703
AlibabaTrojanPSW:Win32/GameThief.5ac2a453
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.VB.NKQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.RiskGen.cxpsiq
TencentWin32.Trojan.Rogue.Pcsz
ComodoMalware@#2u9urexs57cly
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!41CD78F75388
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
IkarusTrojan-GameThief.Win32.OnLineGames
FortinetRiskware/InstallCore
AVGWin32:Malware-gen

How to remove Win32/PSW.VB.NKQ?

Win32/PSW.VB.NKQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment