Malware

Win32:VB-NIE [Trj] (file analysis)

Malware Removal

The Win32:VB-NIE [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-NIE [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-NIE [Trj]?


File Info:

name: EE014FA92B06F6F48798.mlw
path: /opt/CAPEv2/storage/binaries/d92cb0f33b5de7e0eed3c2c75ec6cc824364ddabf5af051e990d96da6a23a61a
crc32: 377D55D4
md5: ee014fa92b06f6f4879834ed6023af70
sha1: 13b59f25317f970b030da82c91c25d777da996fb
sha256: d92cb0f33b5de7e0eed3c2c75ec6cc824364ddabf5af051e990d96da6a23a61a
sha512: 266b8bf09f185e2508482ebdb47672d26766e330cb0e72507af8030a35d2d4cdc84e501874c8b9c836accef3f0bbabf416378fc472e0eeef4006bf1f75dee4b9
ssdeep: 768:0bVmABHHDr/VTnPHBYClqvcB2bxMfaVQDe50sR6/w1+jUZvqBcyulgXY9SycIn+U:8hYD8Wq2oS+Ljb3ts0E9t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED4373AA3B876927E49223367D55C1C7E13370817E4BC2C3B7DAB7251D1EE124429793
sha3_384: 1569b4d1e6ed259d02c8232f441009b029be864b9956ec2447713ad807c5a959c6b8d8ba32334fd3ade0f91ae7cdc7e1
ep_bytes: 6814124000e8f0ffffff000000000000
timestamp: 2000-01-01 12:00:00

Version Info:

0: [No Data]

Win32:VB-NIE [Trj] also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li8h
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.2
FireEyeGeneric.mg.ee014fa92b06f6f4
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.qm
McAfeeVBObfus
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.VBNA.Win32.93368
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.05e5d067
K7GWEmailWorm ( 00568eb41 )
K7AntiVirusEmailWorm ( 00568eb41 )
ArcabitTrojan.Chinky.2
BitDefenderThetaAI:Packer.1EAB3F931E
VirITWorm.Win32.Autorun.DJ
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.GJ
APEXMalicious
TrendMicro-HouseCallWORM_VBNA.SM
Paloaltogeneric.ml
ClamAVWin.Trojan.Chinky-2
KasperskyWorm.Win32.Vobfus.exhg
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.Vobfus.egwnbv
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus[WV]
AvastWin32:VB-NIE [Trj]
TencentWorm.Win32.VBna.c
EmsisoftGen:Trojan.Chinky.2 (B)
BaiduWin32.Worm.VB.jn
F-SecureWorm:W32/Vinkus.gen!A
DrWebWin32.HLLW.Autoruner.8325
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VBNA.SM
Trapminemalicious.high.ml.score
SophosTroj/Vobfus-CP
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminWorm/VBNA.gwlk
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/VB.X.gen!Eldorado
Antiy-AVLTrojan[AutoRun]/Win32.VB.gj
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.VBNA.~gen@1qlvkj
MicrosoftWorm:Win32/Vobfus.F
ViRobotWorm.Win32.VBNA.57344.AIH
ZoneAlarmWorm.Win32.Vobfus.exhg
GDataGen:Trojan.Chinky.2
CynetMalicious (score: 100)
AhnLab-V3Win32/Vbna2.worm.Gen
Acronissuspicious
VBA32SScope.Trojan.VB.Svchorse.027
ALYacGen:Trojan.Chinky.2
Cylanceunsafe
PandaW32/Autorun.JND
RisingTrojan.Autorun!1.DA78 (CLASSIC)
YandexTrojan.GenAsa!Nmq1GgqIrOs
IkarusTrojan.Autorun
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:VB-NIE [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.exhg

How to remove Win32:VB-NIE [Trj]?

Win32:VB-NIE [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment