Malware

Should I remove “Win32:VB-NZU [Drp]”?

Malware Removal

The Win32:VB-NZU [Drp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:VB-NZU [Drp] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:VB-NZU [Drp]?


File Info:

name: 6D45B5AA56F9DAFF3C53.mlw
path: /opt/CAPEv2/storage/binaries/01e76d0690be719fd4bc297b64374b85876be06f79c81333db546808b4764bde
crc32: 4368AAD6
md5: 6d45b5aa56f9daff3c53608908dbbb70
sha1: acec4e0f96c9bf7532a8f73f04eb6de08acc4f44
sha256: 01e76d0690be719fd4bc297b64374b85876be06f79c81333db546808b4764bde
sha512: 2620dd3c02971b22d66b545a3077d374b2788a2cd9762be16452696c75fd8d989e81b84bcab17f92ec9fa75bcd4f3f25c87365a1c14169f6a06e3e59f4033760
ssdeep: 768:fOLCdsbtl28xGEZMke1/B/uBJK0KVMfsRyRFBoytfDN/SBnGHbAEUDiN:fmlTxdXeZNbirbAgN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E583C5FA7C97505BD568823B33ABCAD51503390CAF57554627AD2FEE5E04F02893E223
sha3_384: 398faced865745974e2b3a25c96e4e4615a2ca101e552e4dfd50efa3b24ef72fe8b854a134502ddf06d6228194c558b3
ep_bytes: 68f0124000e8eeffffff000000000000
timestamp: 2009-12-13 14:11:44

Version Info:

Translation: 0x0409 0x04b0
CompanyName: LIIxORZy
ProductName: LIIxORZy
FileVersion: 7.60
ProductVersion: 7.60
InternalName: LIIxORZy
OriginalFilename: LIIxORZy.exe

Win32:VB-NZU [Drp] also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-NZU [Drp]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.2
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.mm
McAfeeVBObfus
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Chinky.2
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
K7GWNetWorm ( 700000151 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Autorun.z
VirITTrojan.Win32.VB.AIRD
SymantecW32.SillyFDC
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.IO
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Vobfus-9805080-0
KasperskyWorm.Win32.Vobfus.exhw
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.VB.covkxf
AvastWin32:VB-NZU [Drp]
RisingWorm.Autorun!1.D162 (CLASSIC)
EmsisoftGen:Trojan.Chinky.2 (B)
F-SecureTrojan:W32/Hutpic.gen!D
DrWebTrojan.Siggen.36675
TrendMicroWORM_ESFURY.SMA
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.6d45b5aa56f9daff
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.D.gen!Eldorado
AviraTR/Agent.mywo.9
MAXmalware (ai score=81)
Antiy-AVLTrojan[Downloader]/Win32.Small
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.F
XcitiumWorm.Win32.AutoRunVB.IO0@1lq9ge
ArcabitTrojan.Chinky.2
ZoneAlarmWorm.Win32.Vobfus.exhw
GDataGen:Trojan.Chinky.2
GoogleDetected
AhnLab-V3Win32/Vbna.Worm6.Gen
Acronissuspicious
BitDefenderThetaAI:Packer.0D4A4BA720
ALYacGen:Trojan.Chinky.2
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaW32/Vobfus.CP.worm
TrendMicro-HouseCallWORM_ESFURY.SMA
TencentWorm.Win32.Vobfus.fd
YandexTrojan.GenAsa!BuQA6xuGzUk
IkarusVirus.Worm
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
ZonerTrojan.Win32.138293
Cybereasonmalicious.a56f9d
DeepInstinctMALICIOUS
alibabacloudWorm.Win.Vobfus.5ea51f66

How to remove Win32:VB-NZU [Drp]?

Win32:VB-NZU [Drp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment