Worm

How to remove “Worm.Win32.VBNA.abvh”?

Malware Removal

The Worm.Win32.VBNA.abvh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VBNA.abvh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.VBNA.abvh?


File Info:

name: E9223683D0102CF2021F.mlw
path: /opt/CAPEv2/storage/binaries/dd8d4528b81b62a17849cb28d8515cb0ad3806c8649b5609bf6272656ea18e28
crc32: E0060966
md5: e9223683d0102cf2021fb3dc0b736bf8
sha1: d317d649efdcbc776aa1e8b49e0f292365f2025d
sha256: dd8d4528b81b62a17849cb28d8515cb0ad3806c8649b5609bf6272656ea18e28
sha512: 1abe30298ed24e1f8b6448f9b030a63766d67e057028b26400602c12a83cbcf096693b5cfa91f2cf4cb75aece02f6295de8ab96d9dceff519ba3187a7917b24a
ssdeep: 1536:vNLg8r8QkGKJv7Kp3StjEMjmLM3ztDJWZsXy4JzxPM0:+GKJvJJjmLM3zRJWZsXy4J9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14533C67AFD57D40AC80853F63B6389D12133745C1A8B265EB6EA1F7D6C20E1448BBE63
sha3_384: 2cc34ba58e9b20e641ce88ed252c909ad57670befe7a1d816ba4c5dfecdf0cf644deb7ab7ff7a0d50f485a2e9146999c
ep_bytes: 6840124000e8eeffffff000000000000
timestamp: 2010-02-22 13:17:41

Version Info:

Translation: 0x0409 0x04b0
ProductName: uujOqdkA
FileVersion: 1.19
ProductVersion: 1.19
InternalName: uujOqdkA
OriginalFilename: uujOqdkA.exe

Worm.Win32.VBNA.abvh also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li7E
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.32984
FireEyeGeneric.mg.e9223683d0102cf2
SkyhighBehavesLike.Win32.VBObfus.qm
McAfeeVbObfus.k
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 004cb3a81 )
AlibabaWorm:Win32/vobfus.1030
K7GWP2PWorm ( 004cb3a81 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Babar.D80D8
BitDefenderThetaAI:Packer.A2D74D6320
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.LR
APEXMalicious
ClamAVHtml.Trojan.VBChinky-2
KasperskyWorm.Win32.VBNA.abvh
BitDefenderGen:Variant.Babar.32984
NANO-AntivirusTrojan.Win32.Drop.cfioo
AvastWin32:AutoRun-BHP [Wrm]
TencentWorm.Win32.VBna.aab
TACHYONTrojan/W32.Chinky.54272
EmsisoftGen:Variant.Babar.32984 (B)
BaiduWin32.Worm.Autorun.z
F-SecureWorm.WORM/VBNA.abvj
DrWebTrojan.MulDrop1.4017
VIPREGen:Variant.Babar.32984
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-C
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.D.gen!Eldorado
AviraWORM/VBNA.abvj
Antiy-AVLTrojan/Win32.VB
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.VBNA.abvj0@1p8jwp
MicrosoftWorm:Win32/Vobfus.AC
ZoneAlarmWorm.Win32.VBNA.abvh
GDataGen:Variant.Babar.32984
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.VBNA.R20505
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Variant.Babar.32984
MAXmalware (ai score=89)
Cylanceunsafe
PandaW32/Vobfus.DN
RisingTrojan.Autorun!1.DA78 (CLASSIC)
YandexTrojan.GenAsa!jN1HHkWAg9U
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:AutoRun-BHP [Wrm]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.Win32.VBNA.abvh?

Worm.Win32.VBNA.abvh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment