Worm

Worm.WbnaMF.S27266067 malicious file

Malware Removal

The Worm.WbnaMF.S27266067 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.WbnaMF.S27266067 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.WbnaMF.S27266067?


File Info:

name: 751107DE3BC86AA41F65.mlw
path: /opt/CAPEv2/storage/binaries/343ea180ac7b509ef78475936d4237f7fbcea906e84064fc0b5d32ceb91c01e2
crc32: 0FEBE363
md5: 751107de3bc86aa41f65da8146063787
sha1: 1b25baac5855c33b91c1ed84891cea0f4f31c6f2
sha256: 343ea180ac7b509ef78475936d4237f7fbcea906e84064fc0b5d32ceb91c01e2
sha512: 8382ad57b20ff87bf61b15dbd2fddcdc85883a81ff32811e371d381b238ec6348f065157facee904897c94c93d62e7ed836bd6c555b646e942902378b2140005
ssdeep: 6144:oANxa2WGk1Y3nmQcuyKQ5DzEJewavj9+zU5StNp:lW2WGk1Y3nmQcjKAPEJlb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E7474617F66F982E045163ED3E9CBB606066CBE2D07D2CBC635369A5EF1E17080A533
sha3_384: c4c7cf590bdf63b298f7022ab51a27dfef903b0a5b1aaf7b78c6a5b893e0f55d756cd4a8e1fda277104b3f557cfef546
ep_bytes: 683c134000e8eeffffff000000000000
timestamp: 2012-08-31 18:48:41

Version Info:

Translation: 0x0409 0x04b0
ProductName: Reshare
FileVersion: 7.65
ProductVersion: 7.65
InternalName: Gastrorrhaphy
OriginalFilename: Gastrorrhaphy.exe

Worm.WbnaMF.S27266067 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
ClamAVWin.Trojan.VB-1734
CAT-QuickHealWorm.WbnaMF.S27266067
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.950
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e3bc86
BaiduWin32.Worm.Pronny.fn
VirITTrojan.Win32.Cryptor.RR
CyrenW32/VB.HD.gen!Eldorado
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.DG
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.tre
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Vobfus.crgjec
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AEIW [Trj]
TencentWorm.Win32.Vobfus.q
TACHYONWorm/W32.WBNA.344064
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/Barys.2644.90
DrWebWin32.HLLW.Autoruner1.25454
TrendMicroWORM_VOBFUS.SMKB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.751107de3bc86aa4
SophosMal/SillyFDC-AC
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Barys.950
JiangminTrojan/Vobfus.sbk
AviraTR/Barys.2644.90
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Barys.950
ViRobotTrojan.Win32.A.Vobfus.344064
ZoneAlarmTrojan.Win32.Vobfus.tre
MicrosoftWorm:Win32/Vobfus.HK
GoogleDetected
AhnLab-V3Trojan/Win32.Vobfus.R35238
VBA32Trojan.Vobfus
ALYacGen:Variant.Barys.950
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMKB
RisingWorm.Pronny!1.6551 (CLASSIC)
IkarusTrojan-Dropper.Vb
MaxSecureTrojan.Malware.6196552.susgen
FortinetW32/Diple.EJQE!tr
BitDefenderThetaAI:Packer.CEF7BD791F
AVGWin32:VB-AEIW [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.WbnaMF.S27266067?

Worm.WbnaMF.S27266067 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment