Worm

How to remove “Worm.Win32.VBNA.baij”?

Malware Removal

The Worm.Win32.VBNA.baij is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VBNA.baij virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.VBNA.baij?


File Info:

name: 55A2FF0D569DC6851AC2.mlw
path: /opt/CAPEv2/storage/binaries/ab7ec373757a87f0b18647f63976c681fcb497e32052bfb226f907450c7be4b8
crc32: 7AE30E62
md5: 55a2ff0d569dc6851ac28c4ffebf0c2a
sha1: 939f312b7866534e4b60d8a76eb907dbbded7be3
sha256: ab7ec373757a87f0b18647f63976c681fcb497e32052bfb226f907450c7be4b8
sha512: 9f426dfac7256bcca51ff1477418ca2597512fa3f641bdb8fd6fac1d260a1f9c6ac1614161f83a1de6b05351e6fc08d944f093a5d0a28a085f5540c240cb551d
ssdeep: 1536:YHQBHqf6cO/h1kGulSc16l6u+NMMl/KlYv1Tq5ThFfNIjnZJX:HphSlu8CFFfCnrX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142A3816737051468E978663423BB8AE739F3A89D0A1B65437B3436385C3FE422D25BD3
sha3_384: 7db4bcc855c5ac896c05c84c00462196e9f5ea63ea46b6b8ac46e64ae23d21402a1a2dd46a43a937703d74b40061065d
ep_bytes: 6820124000e8eeffffff000000000000
timestamp: 2012-04-05 20:59:20

Version Info:

Translation: 0x0409 0x04b0
ProductName: hZgQBvYN
FileVersion: 1.00
ProductVersion: 1.00
InternalName: nFrHfRJSbj
OriginalFilename: nFrHfRJSbj.exe

Worm.Win32.VBNA.baij also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-ACFA [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.82987
FireEyeGeneric.mg.55a2ff0d569dc685
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.nm
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.AutoRun.bc
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AUI
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1687
KasperskyWorm.Win32.VBNA.baij
BitDefenderTrojan.GenericKDZ.82987
NANO-AntivirusTrojan.Win32.VB.rilpe
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ACFA [Trj]
TencentWorm.Win32.Vobfus.h
TACHYONWorm/W32.VBNA.98304
EmsisoftTrojan.GenericKDZ.82987 (B)
F-SecureTrojan.TR/Jorik.vbaayu
DrWebWin32.HLLW.Autoruner1.14616
VIPRETrojan.GenericKDZ.82987
TrendMicroWORM_VOBFUS.SMJA
Trapminemalicious.high.ml.score
SophosW32/Vobfus-AA
IkarusTrojan.Win32.Vobfus
JiangminWorm.WBNA.iiaj
VaristW32/VBInject.CO.gen!Eldorado
AviraTR/Jorik.vbaayu
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1442B
ZoneAlarmWorm.Win32.VBNA.baij
GDataWin32.Worm.Vobfus.H
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R23055
Acronissuspicious
VBA32Worm.WBNA
MAXmalware (ai score=87)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMJA
RisingWorm.Vobfus!1.99C5 (CLASSIC)
YandexTrojan.GenAsa!NJz+QeX5uVg
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.AU!tr
BitDefenderThetaAI:Packer.FFF3D4E120
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.a56de9bd

How to remove Worm.Win32.VBNA.baij?

Worm.Win32.VBNA.baij removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment