Malware

Win32/VB.NQR removal instruction

Malware Removal

The Win32/VB.NQR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.NQR virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/VB.NQR?


File Info:

crc32: 943033C7
md5: b98018869e96a0d6a97c8c2044b74a58
name: B98018869E96A0D6A97C8C2044B74A58.mlw
sha1: c25b606c032e793eb1c9c0e0a135ff5d8cb6eb76
sha256: 48de6070aabced022a2318314628f6e0f16bdba9e5191cfa6331ff436ce2fbd9
sha512: 7dd17be3f68851517f9d7cb106609895545336fa34dbec42a2b24f152381d19c5977799e2cc9b903debed7f7fc40442924de66216981d72193819c6a3f3d78d7
ssdeep: 6144:tHkLT4ijUVyNZsRr1YiD4py/+XOyqoFNfht:Rk3xZm9Uy/zO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Microsoft
InternalName: NetworkApp
FileVersion: 5.00
CompanyName: Microsoft
LegalTrademarks: Microsoft
Comments: Network
ProductName: Network
ProductVersion: 5.00
FileDescription: Network
OriginalFilename: NetworkApp.exe

Win32/VB.NQR also known as:

K7AntiVirusP2PWorm ( 000475b41 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.56972
CynetMalicious (score: 99)
ALYacGen:Trojan.Heur.om0@cHEDIUdi
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.51f8e3dd
K7GWP2PWorm ( 000475b41 )
Cybereasonmalicious.69e96a
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/VB.NQR
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Worm.Vobfus-7460272-0
KasperskyTrojan-Ransom.Win32.Blocker.jfxx
BitDefenderGen:Trojan.Heur.om0@cHEDIUdi
NANO-AntivirusTrojan.Win32.VB.evqlvm
MicroWorld-eScanGen:Trojan.Heur.om0@cHEDIUdi
TencentWin32.Trojan.Blocker.Pgwe
Ad-AwareGen:Trojan.Heur.om0@cHEDIUdi
SophosMal/Generic-S
ComodoTrojWare.Win32.VB.NMV@4yuc48
BitDefenderThetaAI:Packer.FE1CC7261C
VIPRETrojan.Win32.Generic!BT
TrendMicroWORM_POSFIGHT.SMFLK
McAfee-GW-EditionBehavesLike.Win32.Trojan.dm
FireEyeGeneric.mg.b98018869e96a0d6
EmsisoftGen:Trojan.Heur.om0@cHEDIUdi (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.qym
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.22EC99B
MicrosoftTrojan:Win32/Krilog.A
GDataGen:Trojan.Heur.om0@cHEDIUdi
McAfeeArtemis!B98018869E96
MAXmalware (ai score=100)
VBA32TrojanRansom.Blocker
PandaTrj/GdSda.A
TrendMicro-HouseCallWORM_POSFIGHT.SMFLK
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.JFXX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/VB.NQR?

Win32/VB.NQR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment