Malware

How to remove “Win32/VB.NWX”?

Malware Removal

The Win32/VB.NWX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.NWX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32/VB.NWX?


File Info:

name: 83385144CE771E831E58.mlw
path: /opt/CAPEv2/storage/binaries/027d31d3bf480b168b25e4f5e57797d81b69d32fd6faf9c9540cffd2abc2e590
crc32: 507E569C
md5: 83385144ce771e831e5820d3afb428c8
sha1: e49dcad617869bd95a4921189d529115dc5b28be
sha256: 027d31d3bf480b168b25e4f5e57797d81b69d32fd6faf9c9540cffd2abc2e590
sha512: ec14a5675e28170b0bd8ab0eb3d23844e84726cd95e2a99dfe834500072e357bc696eec432565451b7c062aa769558cb4f9e94189a4c625a9249e884cfea97ad
ssdeep: 3072:REAK6CXwF+X4g+RXujvcKPUJlZnPo1IpME831bIkI8SZIP90DU6MwsEyPgEwqgvj:OPu6EtlNV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154B30D3CA0E15803F587757076B3C2B6006AE48D6E1AA5CD21B2CADD5B29FC4D1ECB5B
sha3_384: 90673d87003abf3733b9be02835382ce2ba744d5153fb6ddf7de3491554be7661ce63fac2ae58406309510ea9dbefbbf
ep_bytes: 68a8124000e8eeffffff000040000000
timestamp: 2010-07-18 10:32:32

Version Info:

Translation: 0x0409 0x04b0
ProductName: gyu7
FileVersion: 3.67
ProductVersion: 3.67
InternalName: bnGFKwDT
OriginalFilename: bnGFKwDT.exe

Win32/VB.NWX also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.PonyStealer.MLT.1
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeDownloader-CJX.gen.e
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 00568ebc1 )
K7AntiVirusEmailWorm ( 00568ebc1 )
ArcabitTrojan.PonyStealer.MLT.1
BaiduWin32.Trojan.AutoRun.az
VirITTrojan.Win32.Scar.LM
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.NWX
APEXMalicious
TrendMicro-HouseCallWORM_VBNA.SMN
ClamAVWin.Worm.VB-1131
KasperskyWorm.Win32.Vobfus.dlcn
BitDefenderGen:Heur.PonyStealer.MLT.1
NANO-AntivirusTrojan.Win32.VB.cojahv
SUPERAntiSpywareTrojan.Agent/Gen-FakeAV
AvastWin32:AutoRun-BLX [Wrm]
TencentWorm.Win32.Vobfus.kav
EmsisoftGen:Heur.PonyStealer.MLT.1 (B)
F-SecureWorm:W32/Vobfus.gen!K
DrWebTrojan.MulDrop1.39613
VIPREGen:Heur.PonyStealer.MLT.1
TrendMicroWORM_VBNA.SMN
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.83385144ce771e83
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
JiangminWorm.WBNA.ihmv
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Drop.Age.115200
VaristW32/Vobfus.E.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.SWA@527lh3
MicrosoftWorm:Win32/Vobfus!pz
ZoneAlarmWorm.Win32.Vobfus.dlcn
GDataGen:Heur.PonyStealer.MLT.1
CynetMalicious (score: 100)
AhnLab-V3Win32/Vbna4.worm.Gen
BitDefenderThetaGen:NN.ZevbaF.36802.hm0@a8mTg1li
VBA32Worm.VBNA
Cylanceunsafe
PandaW32/Autorun.JZS
RisingWorm.VobfusEx!1.99E0 (CLASSIC)
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.5557811.susgen
FortinetW32/Injector.ADYA!tr
AVGWin32:AutoRun-BLX [Wrm]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Win32/VB.NWX?

Win32/VB.NWX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment