Worm

Should I remove “Worm.Win32.VB.cz”?

Malware Removal

The Worm.Win32.VB.cz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VB.cz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Worm.Win32.VB.cz?


File Info:

name: 36A5B718DFDC0E306AF8.mlw
path: /opt/CAPEv2/storage/binaries/52200ad69ef392e029583c0a438f2b786d14c03ea075692b55be66307f4159e7
crc32: 15CD3AD3
md5: 36a5b718dfdc0e306af815e04e0739e1
sha1: 6accc616b08ab03ccd06fa74460659765c6b5b62
sha256: 52200ad69ef392e029583c0a438f2b786d14c03ea075692b55be66307f4159e7
sha512: b0caf5ae67d259508bdfe538c1425dba468e15e2f5b0e20e3161ee5704ca2e5e79a0be3d5d64fcaa3110016f2c26eb1c85bc4b54d28734278fbada430289bfe9
ssdeep: 1536:opOvDsD9r3yAgf3TN2s+zheW6BVrqzCJ3bdDY+W14N4NmzWlIA7hKRQqgt1fI:tfbfZ2lQBV+UdE+rECWp7hKPG1fI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A025D080374647FDE2244838341C7B5995E2DE3D08AF215AD317398AAE7DA139BC9B1B
sha3_384: bfb63d0332c693438a37227c7a50500521ae333373e5843cc69301e99ece3a872fc6b39e521405687697e91af493d69d
ep_bytes: b85cb141005064ff3500000000648925
timestamp: 2004-03-08 01:57:36

Version Info:

0: [No Data]

Worm.Win32.VB.cz also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.8iZarLbK@3kab
FireEyeGeneric.mg.36a5b718dfdc0e30
McAfeeW32/MoonLight.worm.c
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0040f8c11 )
K7GWEmailWorm ( 0040f8c11 )
Cybereasonmalicious.8dfdc0
VirITWorm.Win32.VB.T
CyrenW32/VB.MF.gen!Eldorado
SymantecW32.Rontokbro@mm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.EAOA
APEXMalicious
ClamAVWin.Worm.VB-556
KasperskyWorm.Win32.VB.cz
BitDefenderGen:Trojan.Heur.8iZarLbK@3kab
NANO-AntivirusTrojan.Win32.VB.crsvto
AvastWin32:Pioneer-C
TencentMalware.Win32.Gencirc.10b0fe9d
Ad-AwareGen:Trojan.Heur.8iZarLbK@3kab
SophosMal/Generic-R + Mal/VBInject-F
ComodoWorm.Win32.VB.wdr@2nrss7
F-SecureMalware.W32/Floxif.iic
DrWebTrojan.MulDrop.59624
McAfee-GW-EditionW32/MoonLight.worm.c
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.8iZarLbK@3kab (B)
IkarusTrojan.Win32.Agent
GDataGen:Trojan.Heur.8iZarLbK@3kab
JiangminI-Worm/VB.acj
AviraW32/Floxif.iic
ArcabitTrojan.Heur.E669BF
ZoneAlarmWorm.Win32.VB.cz
MicrosoftWorm:Win32/Lightmoon.H
CynetMalicious (score: 100)
AhnLab-V3HEUR/Fakon.mwf.X1381
Acronissuspicious
BitDefenderThetaAI:Packer.0031DFDE1D
ALYacGen:Trojan.Heur.8iZarLbK@3kab
MAXmalware (ai score=83)
VBA32Trojan.Wacatac
MalwarebytesNimnul.Virus.FileInfector.DDS
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
YandexWorm.VB!w+uCpxMh8fA
SentinelOneStatic AI – Suspicious PE
FortinetW32/Moonlight.C!worm
AVGWin32:Pioneer-C
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.Win32.VB.cz?

Worm.Win32.VB.cz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment