Worm

Worm.VBNA removal

Malware Removal

The Worm.VBNA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.VBNA virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
ns1.player1253.com
ns1.videoall.net
ns1.mediashares.org

How to determine Worm.VBNA?


File Info:

crc32: 9F6E1689
md5: 28d8a7e5c5d92a7efab49144fe6d6aae
name: 28D8A7E5C5D92A7EFAB49144FE6D6AAE.mlw
sha1: fdd06b8303a850b343832d3074688b252704c894
sha256: 76c7535f3e00da0e6bb40e93978c541dc5b7853d97906ee55c5751bb1818dab8
sha512: 85835de1e59cc1c96827e45074fd9fa0d8513fa11f42a74049753880f43ac4fd55fd438ba47dfb90b4d2b1ab0c8a538b4b5c83c7f0b977c7f2d62f0074f8429f
ssdeep: 1536:rbxoF7vst+SbtS0SIImNMlsCSZxIG+UkHoc:WvzRfloc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: z5KSssw
FileVersion: 6.50
CompanyName: UserXP
ProductName: 932KSssw
ProductVersion: 6.50
OriginalFilename: z5KSssw.exe

Worm.VBNA also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.28d8a7e5c5d92a7e
CAT-QuickHealWorm.VBNA
McAfeeDownloader-CJX.gen.l
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Purora.a (v)
SangforMalware
K7AntiVirusTrojan-Downloader ( 001f4fd41 )
BitDefenderGen:Variant.Symmi.6639
K7GWTrojan-Downloader ( 001f4fd41 )
Cybereasonmalicious.5c5d92
BaiduWin32.Worm.AutoRun.cj
CyrenW32/VB.BT.gen!Eldorado
SymantecW32.Changeup!gen20
TotalDefenseWin32/Vobfus.F!generic
APEXMalicious
AvastWin32:AutoRun-BSJ [Trj]
CynetMalicious (score: 100)
KasperskyWorm.Win32.VBNA.brlr
AlibabaWorm:Win32/Purora.13463d06
NANO-AntivirusTrojan.Win32.Mlw.iejaqv
ViRobotTrojan.Win32.Downloader.61440.UJ
MicroWorld-eScanGen:Variant.Symmi.6639
TencentWin32.Worm.Vbna.Htwi
Ad-AwareGen:Variant.Symmi.6639
SophosML/PE-A + Troj/VB-KVR
ComodoTrojWare.Win32.VB.X@2i170u
F-SecureTrojan:W32/Vbkrypt.D
DrWebTrojan.Packed.21297
TrendMicroWORM_VOBFUS.SMIA
McAfee-GW-EditionBehavesLike.Win32.Downloader.mz
EmsisoftGen:Variant.Symmi.6639 (B)
SentinelOneStatic AI – Malicious PE – Worm
JiangminWorm/VBNA.gxfn
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftTrojanDownloader:Win32/Purora
SUPERAntiSpywareTrojan.Agent/Gen-Obfuscator
ZoneAlarmWorm.Win32.VBNA.brlr
GDataGen:Variant.Symmi.6639
AhnLab-V3Trojan/Win32.VBKrypt.R32907
Acronissuspicious
BitDefenderThetaAI:Packer.2F75715320
ALYacGen:Variant.Symmi.6639
TACHYONWorm/W32.VBNA.90112
VBA32SScope.Trojan.VBRA.2842
MalwarebytesPurora.Worm.VB.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/AutoRun.VB.XY
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingTrojan.Win32.VBCode.cbu (CLASSIC)
YandexTrojan.GenAsa!LeaBETo6kWM
IkarusTrojan-Dropper
FortinetW32/Virtu.F
AVGWin32:AutoRun-BSJ [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/TrojanDownloader.Purora.HwMABh8A

How to remove Worm.VBNA?

Worm.VBNA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment