Malware

About “Win32/VB.NSP” infection

Malware Removal

The Win32/VB.NSP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.NSP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Installs a browser addon or extension
  • The executable is compressed using UPX
  • Sniffs keystrokes
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/VB.NSP?


File Info:

crc32: 960E993F
md5: 76f45ab82522d27c7ed72fda7ee119b1
name: 76F45AB82522D27C7ED72FDA7EE119B1.mlw
sha1: 142d52cd203b715310e9cf627eed065f23795ae2
sha256: 4e3e35a89f8105c2746d77801c92fb12d121e17714a3ea2c41faa1b14f40bc11
sha512: c01536b1423e6deb3d1d568a845439a6553cc3a3de068fcef1e2f1bb7e9fdb921b85c04898b26273331e99a1184aee819028e90feb0546c4895688d9b6c7923d
ssdeep: 3072:AytrlBREwZN8OcIaR3qFe0jV75moGEazI0:AyI+NWB45mTf9
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: pikachu
FileVersion: 1.00
OriginalFilename: pikachu.exe
ProductName: Project1

Win32/VB.NSP also known as:

BkavW32.GenericAutorunnerGTC.Worm
LionicTrojan.Win32.Generic.l08m
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.63822
ClamAVLegacy.Trojan.Agent-1388589
ALYacTrojan.Generic.7814978
CylanceUnsafe
ZillyaWorm.VB.Win32.1215
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005640b91 )
K7AntiVirusTrojan ( 005640b91 )
TrendMicroWORM_VB.SMLF
BaiduWin32.Worm.VB.rw
CyrenW32/Worm.ZIHN-5263
SymantecTrojan Horse
ESET-NOD32Win32/VB.NSP
APEXMalicious
TotalDefenseWin32/Veebuu.LI
AvastWin32:Sality
CynetMalicious (score: 100)
KasperskyWorm.Win32.VB.aqj
BitDefenderTrojan.Generic.7814978
NANO-AntivirusTrojan.Win32.ULPM.csfhee
ViRobotWorm.Win32.VB.222208
MicroWorld-eScanTrojan.Generic.7814978
TencentWorm.Win32.Autorun.d
Ad-AwareTrojan.Generic.7814978
SophosMal/VB-F
ComodoWorm.Win32.Autorun.eb0@13re4o
F-SecureTrojan.TR/Crypt.ULPM.Gen
BitDefenderThetaAI:Packer.14C640F11C
VIPRETrojan.Win32.Generic.pak!cobra
InvinceaML/PE-A + Mal/VB-F
McAfee-GW-EditionBehavesLike.Win32.Swisyn.cm
FireEyeGeneric.mg.76f45ab82522d27c
EmsisoftTrojan.Generic.7814978 (B)
SentinelOneDFI – Malicious PE
JiangminWorm/VB.asz
WebrootW32.Worm.ANTM
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLWorm/Win32.VB
KingsoftWin32.Virut.ce.57344
MicrosoftTrojanDropper:Win32/Gepys
ArcabitTrojan.Generic.D773F42
SUPERAntiSpywareTrojan.Agent/Gen-Pikachu
ZoneAlarmWorm.Win32.VB.aqj
GDataTrojan.Generic.7814978
AhnLab-V3HEUR/Fakon.mwf.X1381
Acronissuspicious
McAfeeW32/Worm-FEL!76F45AB82522
MAXmalware (ai score=100)
VBA32Trojan.VBS.01911
MalwarebytesTrojan.Agent
PandaAdware/AccesMembre
TrendMicro-HouseCallWORM_VB.SMLF
RisingWorm.VobfusEx!1.99E4 (CLASSIC)
YandexWorm.VB!YUKi7rAFDWY
IkarusWorm.Win32.VB
FortinetW32/Generic.AP.298EDE!tr
AVGWin32:Sality
Paloaltogeneric.ml
Qihoo-360Win32/Worm.b65

How to remove Win32/VB.NSP?

Win32/VB.NSP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment