Worm

What is “Worm.Win32.VBNA.brmq”?

Malware Removal

The Worm.Win32.VBNA.brmq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VBNA.brmq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.VBNA.brmq?


File Info:

name: 8173A6AB9E71E1BB0767.mlw
path: /opt/CAPEv2/storage/binaries/61ab83b98784120d0e59ef5e454c75cda952d12191e73e99b66459cded59ff54
crc32: 1E69C8F8
md5: 8173a6ab9e71e1bb0767c7b5fd4687f5
sha1: c2f454d67a9913605247a9b74c1d043f8b42885b
sha256: 61ab83b98784120d0e59ef5e454c75cda952d12191e73e99b66459cded59ff54
sha512: 8aa2fa12c6bc01745a25b36d7ead163077f59ead6b62b403472f77e4b97964a61c8689484ab520f1ef1bddd323bcf97ac88402855c2dd7e8c85781d95cca64ce
ssdeep: 1536:SuwcLjQgnRt9UdLw6BNMyBhXZxHJ6P6D5f:4gz07JjD5f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B243B26B7385182ADB0CA23536A7C7E71AD7B48E075F5A4357B823799C24F412D12F13
sha3_384: 58c51b0af1f4081c18220fc12b256aab287fca56193fbbf162ea83e84ed42ead57632ab046b57230ffc243076b2779ea
ep_bytes: 6880114000e8f0ffffff000000000000
timestamp: 2010-12-28 13:10:07

Version Info:

Translation: 0x0409 0x04b0
CompanyName: UserXP
ProductName: 4322VBRUN
FileVersion: 6.48
ProductVersion: 6.48
InternalName: AARRo99
OriginalFilename: AARRo99.exe

Worm.Win32.VBNA.brmq also known as:

Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.40364
MicroWorld-eScanGen:Variant.Symmi.719
CAT-QuickHealWorm.VbnaMF.S22387683
McAfeeDownloader-CJX.gen.o
CylanceUnsafe
K7AntiVirusTrojan ( 001e96331 )
K7GWTrojan ( 001e96331 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.123AFE6920
VirITTrojan.Win32.Shiru.AY
CyrenW32/VB.BT.gen!Eldorado
SymantecW32.Changeup!gen10
ESET-NOD32Win32/AutoRun.VB.XY
TrendMicro-HouseCallWORM_VOBFUS.SMIA
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.VBNA.brmq
BitDefenderGen:Variant.Symmi.719
NANO-AntivirusTrojan.Win32.VB.cooocg
ViRobotTrojan.Win32.Generic.57344.H
AvastWin32:AutoRun-BSS [Wrm]
Ad-AwareGen:Variant.Symmi.719
EmsisoftGen:Variant.Symmi.719 (B)
ComodoTrojWare.Win32.VB.XYT@59rakd
BaiduWin32.Worm.AutoRun.cj
TrendMicroWORM_VOBFUS.SMIA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.qt
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.8173a6ab9e71e1bb
SophosML/PE-A + Mal/SillyFDC-I
IkarusTrojan-Dropper
GDataGen:Variant.Symmi.719
JiangminTrojan/VBKrypt.hart
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
MicrosoftVirTool:Win32/Obfuscator.NM
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Changeup.R2716
Acronissuspicious
VBA32SScope.Trojan.VBRA.9611
TACHYONTrojan/W32.VB-Agent.57344.LW
MalwarebytesMalware.AI.4214291897
APEXMalicious
TencentWorm.Win32.Vbna.zf
MAXmalware (ai score=82)
MaxSecureWorm.Worm.W32.VBNA.brmq
FortinetW32/VBKrypt.AGW!tr
AVGWin32:AutoRun-BSS [Wrm]
Cybereasonmalicious.b9e71e
PandaGeneric Malware

How to remove Worm.Win32.VBNA.brmq?

Worm.Win32.VBNA.brmq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment