Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

Worm.Win32.VBNA.aitt removal instruction

Published May 1, 2024 Worm category 3 min read
Report context

What to verify before removal

Use this report for a controlled check of Worm.Win32.VBNA.aitt removal instruction when the affected machine shows suspicious processes, dropped files, or payload delivery behavior. The goal is to verify the exact file and persistence path before quarantine.

Start by comparing the local file name with E549B7BBF339568A67C0.mlw, then review the behavior notes for persistence entries, dropped files, unusual processes, and browser or network changes. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
E549B7BBF339568A67C0.mlw
  • Compare the suspicious file name with E549B7BBF339568A67C0.mlw.
  • Confirm the detection name matches Worm.Win32.VBNA.aitt removal instruction before removing related files.
  • Review the report for persistence entries, dropped files, unusual processes, and browser or network changes so the cleanup is based on observed behavior, not only the label.
  • Run a full scan, quarantine confirmed detections, and restart before signing back in to sensitive accounts.

The Worm.Win32.VBNA.aitt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Worm.Win32.VBNA.aitt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.VBNA.aitt?


File Info:

name: E549B7BBF339568A67C0.mlw
path: /opt/CAPEv2/storage/binaries/56ca85e74393f431be89d1eb15ec659a514be22a84c9689f3a0c89fccdc12a3c
crc32: 45BFE0E9
md5: e549b7bbf339568a67c053ffdc617b0d
sha1: 5191e39e90f99da7397dca03712c1f29b43eeadc
sha256: 56ca85e74393f431be89d1eb15ec659a514be22a84c9689f3a0c89fccdc12a3c
sha512: daa2ca57a719192a3b020f6e8b5be4e41952c33fa121dfc80dd81f761b21b8e4ba28fff5734a775f3e437a0caeabe361ca2c4ccc5c6006a96cceaac691f91a97
ssdeep: 1536:GNcgoNQY1ObCYUXhXAXzXakcUckn98kMEW73:zRG0kcUckn98kMEQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A43716EFE05144BD60D6A313E67CA9F1EB364CE2F4F1A87251873789D36E103825A1B
sha3_384: 7c00a635ef849200c12d847b66e7f57df6b6ffccf732e751f6f6e3afede2fb7a6a5b687cbf682d814f8719c069dca605
ep_bytes: 6874124000e8eeffffff000040000000
timestamp: 2010-07-08 11:37:18

Version Info:

Translation: 0x0409 0x04b0
ProductName: u
FileVersion: 1.47
ProductVersion: 1.47
InternalName: XXqAJjIG
OriginalFilename: XXqAJjIG.exe

Worm.Win32.VBNA.aitt also known as:

Bkav W32.AIDetectMalware
Lionic Worm.Win32.VBNA.lmeS
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
FireEye Generic.mg.e549b7bbf339568a
CAT-QuickHeal Worm.VBNA.gen
Skyhigh BehavesLike.Win32.VBObfus.qm
McAfee Downloader-CJX.d
Cylance unsafe
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( f1000d011 )
Alibaba Worm:Win32/vobfus.1030
K7GW Trojan ( f1000d011 )
Arcabit Trojan.Midie.DEA01
Baidu Win32.Worm.VB.as
VirIT Worm.Win32.VB.12.O
Symantec W32.Changeup
ESET-NOD32 Win32/AutoRun.VB.RD
APEX Malicious
ClamAV Win.Trojan.VB-1146
Kaspersky Worm.Win32.VBNA.aitt
BitDefender Gen:Variant.Midie.59905
NANO-Antivirus Trojan.Win32.Inject.covlpb
MicroWorld-eScan Gen:Variant.Midie.59905
Avast Win32:VB-PQX [Wrm]
Tencent Worm.Win32.VBNA.hew
Emsisoft Gen:Variant.Midie.59905 (B)
F-Secure Worm:W32/Vobfus.AX
DrWeb Trojan.Inject.8955
VIPRE Gen:Variant.Midie.59905
TrendMicro WORM_ESFURY.SMA
Trapmine malicious.high.ml.score
Sophos W32/Autorun-BFG
SentinelOne Static AI – Malicious PE
Webroot W32.Obfuscated.Gen
Varist W32/Vobfus.I.gen!Eldorado
Avira TR/Dldr.Gaat.A
Antiy-AVL Worm/Win32.WBNA.gen
Kingsoft malware.kb.a.1000
Xcitium TrojWare.Win32.VB.SWA@527lh3
Microsoft Worm:Win32/Vobfus.R
ZoneAlarm Worm.Win32.VBNA.aitt
GData Gen:Variant.Midie.59905
Google Detected
AhnLab-V3 Win32/Vbna4.worm.Gen
ALYac Gen:Variant.Midie.59905
MAX malware (ai score=87)
VBA32 Worm.VBNA
Malwarebytes Generic.Malware.AI.DDS
Panda W32/Vobfus.EQ
TrendMicro-HouseCall WORM_ESFURY.SMA
Rising Worm.VobfusEx!1.99EB (CLASSIC)
Yandex Trojan.GenAsa!9Rfy1WXFFUs
Ikarus Worm.Win32.Vobfus
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Injector.ADYA!tr
BitDefenderTheta AI:Packer.4AF00E1E20
AVG Win32:VB-PQX [Wrm]
DeepInstinct MALICIOUS
alibabacloud Trojan.Win.UnkAgent

How to remove Worm.Win32.VBNA.aitt?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.