Malware

Win32/VB.RNU removal tips

Malware Removal

The Win32/VB.RNU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.RNU virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Korean
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/VB.RNU?


File Info:

crc32: 9B74F261
md5: d3c21b97067f7255297f4f921e93857a
name: D3C21B97067F7255297F4F921E93857A.mlw
sha1: f5d5643fb3ef133fec44099042a92748c613580f
sha256: 0a0d8b13fc2533d6cc6a74f345ece1708231f8f6ddcd6901b327224c7b8389b5
sha512: 888d0997504ad37b680cd5adec2bbc61f78f34e610eab87f1c66923d882466e1171fddde4f44556643fba473448db0cd1df92b0a5961a799a86dfb0a0a8b4415
ssdeep: 6144:Mtuh0UrKzA/12cVxzWTYT5BjfabsnUlp:+ENMInU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0412 0x04b0
InternalName: qaznds
FileVersion: 1.00
CompanyName: ADMIN
ProductName: cli
ProductVersion: 1.00
OriginalFilename: qaznds.exe

Win32/VB.RNU also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.VbCrypt.68
ALYacTrojan.Downloader.81986
CylanceUnsafe
SangforTrojan.Win32.VB.8
Cybereasonmalicious.7067f7
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/VB.RNU
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.Heur.om0@sn5TSriGe
NANO-AntivirusTrojan.Win32.VB.edoysb
MicroWorld-eScanGen:Trojan.Heur.om0@sn5TSriGe
TencentWin32.Trojan.Vb.Wrzu
Ad-AwareGen:Trojan.Heur.om0@sn5TSriGe
SophosMal/Generic-S
BitDefenderThetaAI:Packer.872675261D
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.dm
FireEyeGeneric.mg.d3c21b97067f7255
EmsisoftGen:Trojan.Heur.om0@sn5TSriGe (B)
eGambitUnsafe.AI_Score_92%
Antiy-AVLTrojan/Generic.ASMalwS.1C30AC2
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Heur.E7EA73
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Trojan.Heur.om0@sn5TSriGe
AhnLab-V3Trojan/Win32.Agent.C171447
McAfeeArtemis!D3C21B97067F
MAXmalware (ai score=88)
YandexTrojan.GenAsa!Znf9Y3Ir/jQ
IkarusTrojan.Win32.VB
FortinetW32/VB.RNU!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/VB.RNU?

Win32/VB.RNU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment