Worm

What is “Worm.Win32.VBNA.brml”?

Malware Removal

The Worm.Win32.VBNA.brml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VBNA.brml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.VBNA.brml?


File Info:

name: 94D9066F38651FE162D1.mlw
path: /opt/CAPEv2/storage/binaries/20530174e2e0fef68d1816985c82fd1bd809f0862292d871a2ba5b8b35c14f9e
crc32: CBEBDD7F
md5: 94d9066f38651fe162d1ae863a9e0df1
sha1: ffca437282347de5b7935fbca26b66f0df0a6843
sha256: 20530174e2e0fef68d1816985c82fd1bd809f0862292d871a2ba5b8b35c14f9e
sha512: 0c47add08ec4291285b334c1e5c89815d61d000205ca9fed5ab5846ed89f5b7b450dcfaba270d4fa5cf1a7011856afeb591aa974ecb19003455edf687c8b0ecb
ssdeep: 1536:eIscl1eH067BvmV7NMk91sZxr7OjD5AI:neFY+qD5AI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE53B62A734A1827DB18A2397267C7EB19E3748E4B4F1A832778637DCC64F102D15B67
sha3_384: 2c4e6533900392d0f9c7cdc9d005fd360f6b5a41702599ef7308f023527431c5557f8a228873ed703d7929e06581f8d5
ep_bytes: 68b0114000e8eeffffff000000000000
timestamp: 2010-12-25 13:27:19

Version Info:

Translation: 0x0409 0x04b0
ProductName: 8765VBRUN
FileVersion: 5.14
ProductVersion: 5.14
InternalName: GGmox9998
OriginalFilename: GGmox9998.exe

Worm.Win32.VBNA.brml also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li7E
tehtrisGeneric.Malware
DrWebTrojan.MulDrop4.51964
MicroWorld-eScanGen:Variant.Symmi.719
FireEyeGeneric.mg.94d9066f38651fe1
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.kt
McAfeeDownloader-CJX.gen.o
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:Win32/vobfus.1030
K7GWTrojan ( 001e96331 )
K7AntiVirusTrojan ( 001e96331 )
BitDefenderThetaAI:Packer.BEBE325820
VirITTrojan.Win32.Shiru.AY
SymantecW32.Changeup!gen10
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.XY
APEXMalicious
TrendMicro-HouseCallWORM_UTOTI.SMC1
ClamAVWin.Malware.Vobfus-9806879-0
KasperskyWorm.Win32.VBNA.brml
BitDefenderGen:Variant.Symmi.719
NANO-AntivirusTrojan.Win32.VB.covkta
AvastWin32:AutoRun-BSJ [Trj]
TencentWorm.Win32.VBNA.hd
TACHYONTrojan/W32.VB-VBKrypt.61440.D
EmsisoftGen:Variant.Symmi.719 (B)
F-SecureTrojan:W32/Vbkrypt.D
BaiduWin32.Worm.AutoRun.cj
VIPREGen:Variant.Symmi.719
TrendMicroWORM_UTOTI.SMC1
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-I
IkarusTrojan-Dropper
JiangminWorm/VBNA.gyrt
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/VB.BT.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftVirTool:Win32/Obfuscator.NI
XcitiumTrojWare.Win32.VB.X@2i170u
ArcabitTrojan.Symmi.719
ViRobotWorm.Win32.A.VBNA.61440.DC
ZoneAlarmWorm.Win32.VBNA.brml
GDataGen:Variant.Symmi.719
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R2205
Acronissuspicious
VBA32SScope.Trojan.VBRA.2842
ALYacGen:Variant.Symmi.719
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
RisingWorm.Autorun!1.99E9 (CLASSIC)
YandexTrojan.VBKrypt.Gen.8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.AGW!tr
AVGWin32:AutoRun-BSJ [Trj]
Cybereasonmalicious.f38651
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.9dea8c76

How to remove Worm.Win32.VBNA.brml?

Worm.Win32.VBNA.brml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment