Worm

Worm.WBNA removal

Malware Removal

The Worm.WBNA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.WBNA virus can do?

  • Executable code extraction
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Worm.WBNA?


File Info:

crc32: F23DB1E7
md5: 3d7a89ff113705c752d90ce0f8b8a332
name: saierhaoxiaojinglingfuzhuqi_v2.1.exe
sha1: 4d9213019597b98a3ec2ecd309a6d6d29d8d7d06
sha256: b24f0fa44035d1df65ed3814b3f09ff88c409a8e32a383ac7a86f58017f02ae2
sha512: d21b85d380edfc55339df2ad8fc8391194a9ba0b7ed3cd481e8f1a33e540116c6d07d3f2c26a245d849f968328c4ffbf9854b19312919730de8f9516d425fb0b
ssdeep: 3072:+4MlVuT4Ml4MWjH8SG4MsVuW4Ml4MzILFfFJFzOcYDAWJ2cPw/v89rWFKsPut:+LkTbYDa6kWbyFFJ8cA/9ICVt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
LegalCopyright: x6b63x7248
InternalName: x8d5bx5c14x7cbex7075x5c0fx8f85x52a9V2.1
FileVersion: 2.01.0002
CompanyName: seerx5c01x5305x5de5x4f5cx5ba4
LegalTrademarks: x201cx8d5bx5c14x7cbex7075x201dx5b57x6837x6587x5b57
ProductName: x8d5bx5c14x7cbex7075 x8f85x52a9x5de5x5177V2.1
ProductVersion: 2.01.0002
FileDescription: x8d5bx5c14x53f7x7cbex7075x8f85x52a9x5668xff0cx53efx4ee5x5e2ex52a9x4f60x7ec3x7ea7xff0cx6253x602ax7b49x7b49
OriginalFilename: x8d5bx5c14x7cbex7075x5c0fx8f85x52a9V2.1.exe

Worm.WBNA also known as:

MicroWorld-eScanTrojan.GenericKD.42588883
FireEyeTrojan.GenericKD.42588883
McAfeeGenericRXCZ-XJ!3D7A89FF1137
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabWorm.Win32.WBNA.o!c
SangforMalware
K7AntiVirusTrojan ( 0051cb081 )
BitDefenderTrojan.GenericKD.42588883
K7GWTrojan ( 0051cb081 )
Cybereasonmalicious.19597b
TrendMicroTROJ_GEN.R002C0PBG20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Spyware-gen [Spy]
GDataTrojan.GenericKD.42588883
NANO-AntivirusTrojan.Win32.Strictor.ficxbs
TencentWin32.Risk.Adspy.Lmle
SophosMal/Generic-S
ComodoMalware@#2a5ct1ibmbhoe
ZillyaWorm.WBNA.Win32.204851
McAfee-GW-EditionBehavesLike.Win32.Fareit.fc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42588883 (B)
JiangminWorm/WBNA.gamt
WebrootW32.Trojan.Gen
eGambitGeneric.Malware
Antiy-AVLWorm/Win32.WBNA
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D289DAD3
TACHYONWorm/W32.VB-WBNA.331776
AhnLab-V3Worm/Win32.WBNA.R113807
Acronissuspicious
ALYacTrojan.GenericKD.42588883
MAXmalware (ai score=86)
VBA32Worm.WBNA
TrendMicro-HouseCallTROJ_GEN.R002C0PBG20
YandexWorm.WBNA!cP5Si+xWN9k
SentinelOneDFI – Suspicious PE
Ad-AwareTrojan.GenericKD.42588883
AVGWin32:Spyware-gen [Spy]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Worm.WBNA?

Worm.WBNA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment