Malware

Win32:VB-NPD [Wrm] removal instruction

Malware Removal

The Win32:VB-NPD [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-NPD [Wrm] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-NPD [Wrm]?


File Info:

name: 50BC077F88E63231D8A7.mlw
path: /opt/CAPEv2/storage/binaries/cd8733e425bb9e16e4bdfda76ffda9558c9c6d344452d6dc29ee5483e5220499
crc32: C00AF027
md5: 50bc077f88e63231d8a7e2537139cb7f
sha1: 1ef327edb6ce19e05ad1526c6442330ebad55553
sha256: cd8733e425bb9e16e4bdfda76ffda9558c9c6d344452d6dc29ee5483e5220499
sha512: 45e0eac3039cb9633ea0556edd2e05b07f5ad91a4d19ca6517233849396196fe3e6159d58c02caceaa4c5d610c52d8198618dcee55e1f3e51f281f1e60201897
ssdeep: 768:Q23ipFA13weNFSmOEggIzuTJjV+Tnc/9/8IZnS0R0TYWfHenHLqHCTHgpQO0k:9SA1geNFSvEHTP+Tnsx5S0REQO0k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15823946A794796C7E10633BC359B86C13A53B1AA1E0B01E77B5D9B789C12FD10C27B83
sha3_384: 0ff3218b6bb8e4ca4f51c4992eaef87cb9318a9b87c852e04de8c4fb3180198a282181ef2af7f9e40f671dce4df89eba
ep_bytes: 6850124000e8eeffffff000000000000
timestamp: 2009-10-14 17:19:46

Version Info:

CompanyName: 5

Win32:VB-NPD [Wrm] also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-NPD [Wrm]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.2
FireEyeGeneric.mg.50bc077f88e63231
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.pm
McAfeeVBObfus
MalwarebytesChir.Spyware.Infostealer.DDS
ZillyaWorm.VBNA.Win32.62555
SangforSuspicious.Win32.Save.vb
K7GWEmailWorm ( 00568ec61 )
K7AntiVirusEmailWorm ( 00568ec61 )
BaiduWin32.Worm.Agent.ad
VirITWorm.Win32.VBNA.A
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.IQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Chinky-4
KasperskyWorm.Win32.Vobfus.exgy
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.VB.crdovc
SUPERAntiSpywareTrojan.Agent/Gen-AutoR
AvastWin32:VB-NPD [Wrm]
TencentWorm.Win32.VBna.aab
EmsisoftGen:Trojan.Chinky.2 (B)
F-SecureWorm:W32/Vinkus.gen!A
DrWebWin32.HLLW.Autoruner.10717
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VBNA.SMB
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
JiangminWorm/VBNA.hphb
VaristW32/Vobfus.C.gen!Eldorado
AviraTR/VBNA.jii
MAXmalware (ai score=89)
Antiy-AVLTrojan[AutoRun]/Win32.VB
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.F
XcitiumWorm.Win32.VBNA.~gen@1qlvkj
ArcabitTrojan.Chinky.2
ZoneAlarmWorm.Win32.Vobfus.exgy
GDataGen:Trojan.Chinky.2
GoogleDetected
AhnLab-V3Win32/Vbna4.worm.Gen
Acronissuspicious
BitDefenderThetaAI:Packer.D831A87720
ALYacGen:Trojan.Chinky.2
TACHYONWorm/W32.Vobfus.49152.C
VBA32SScope.Trojan.VB.Svchorse.025
Cylanceunsafe
PandaW32/Vobfus.CP.worm
TrendMicro-HouseCallWORM_VBNA.SMB
RisingTrojan.Win32.VBCode.cet (CLASSIC)
YandexTrojan.GenAsa!ZyJMxQzGhIQ
IkarusVirus.Worm.Win32.VBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
ZonerTrojan.Win32.123907
DeepInstinctMALICIOUS

How to remove Win32:VB-NPD [Wrm]?

Win32:VB-NPD [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment