Malware

Win32/VB.NJO malicious file

Malware Removal

The Win32/VB.NJO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.NJO virus can do?

  • Executable code extraction
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/VB.NJO?


File Info:

crc32: 8CDB8D5F
md5: 2a3381a1b4a2c74e4538939a57f7456c
name: 2A3381A1B4A2C74E4538939A57F7456C.mlw
sha1: 717dea34dfb5c2f59e61e2c8d00e7c91f91ea23c
sha256: ccbdca395a843faad64b98d92f669aa1c83ff075108e93f8afc157db75fd9614
sha512: c529a4c8e21957ece4fe9b44ca7efc8e1e63fd650d7a504f5e0bdb45c768f8632233d487cdcf5d9187c5bc7a769de26f08388a09968028a7cf35b604d43e531b
ssdeep: 768:QJo4AggSFM0kWc0AxV1ADmTlWTs/TQJXfOa9NJZ0pC/CX12yJ:QJ3ZgeM0kWA1ADmTlWQ/ciQSMyJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: funy
FileVersion: 1.00
OriginalFilename: funy.exe
ProductName: RealWorm

Win32/VB.NJO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005640b91 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.9438
CynetMalicious (score: 99)
CAT-QuickHealTrojan.VBCrypt.MF.2108
ALYacGen:Trojan.Heur.dm0@fLDB4Bhi
CylanceUnsafe
ZillyaTrojan.Hesv.Win32.697
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005640b91 )
Cybereasonmalicious.1b4a2c
BaiduWin32.Worm.VB.sz
CyrenW32/VBTrojan.17E!Maximus
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VB.NJO
APEXMalicious
AvastWin32:VB-KZN [Wrm]
KasperskyUDS:Trojan.Win32.Hesv.gen
BitDefenderGen:Trojan.Heur.dm0@fLDB4Bhi
NANO-AntivirusTrojan.Win32.VB.edtvhc
ViRobotTrojan.Win32.A.Cosmu.86016.E
SUPERAntiSpywareWorm.VB
MicroWorld-eScanGen:Trojan.Heur.dm0@fLDB4Bhi
TencentMalware.Win32.Gencirc.10b770a4
Ad-AwareGen:Trojan.Heur.dm0@fLDB4Bhi
SophosMal/Generic-S
ComodoTrojWare.Win32.VB.IOK@54rlsj
BitDefenderThetaAI:Packer.5BB4EDE21C
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Ransomware.kt
FireEyeGeneric.mg.2a3381a1b4a2c74e
EmsisoftGen:Trojan.Heur.dm0@fLDB4Bhi (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cosmu.prx
WebrootW32.Malware.Gen
AviraTR/Cosmu.apw.3
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.10FC80E
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Trojan.Heur.dm0@fLDB4Bhi
AhnLab-V3Win32/Autorun.worm.61440.AL
Acronissuspicious
McAfeeArtemis!2A3381A1B4A2
MAXmalware (ai score=84)
VBA32SScope.Trojan.VBRA.12177
MalwarebytesLamer.Virus.FileInfector.DDS
RisingWorm.VB!8.30 (C64:YzY0OqLSo+sGQpdz)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.NZK!tr
AVGWin32:VB-KZN [Wrm]

How to remove Win32/VB.NJO?

Win32/VB.NJO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment