Categories: Worm

About “Worm.Win32.VBNA.brqy” infection

The Worm.Win32.VBNA.brqy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VBNA.brqy virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
ns1.player1253.com
ns1.videoall.net
ns1.mediashares.org

How to determine Worm.Win32.VBNA.brqy?


File Info:

crc32: 898C3A33md5: ed2799b74c60ad5f0e231940130a3e80name: ED2799B74C60AD5F0E231940130A3E80.mlwsha1: 581b6ee6fd46fa0074f205f60b0cd25849268b59sha256: fde6ef3ef8bce6982bd4130cb1c526e49ae41de2c03b2aa4df130465cab004aasha512: 75bbba47864411d9b8f13a2fa58837e53544013f9f69a82ef3bc8167977e50322ce4c11f2b61fc025fda178ffc3401a4b15b52b5d94a18f76d253ba736360111ssdeep: 768:zs1ohAKyt4pd04q0zik+vhy7g0EM/LinbQ+au0i:IcAKeEn3+pCg0EUGQ+type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0ProductVersion: 9.69InternalName: RyyMZFileVersion: 9.69OriginalFilename: RyyMZ.exeProductName: RyyMZO

Worm.Win32.VBNA.brqy also known as:

Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.45597316
FireEye Generic.mg.ed2799b74c60ad5f
CAT-QuickHeal Worm.VBNA.gen
ALYac Trojan.GenericKD.45597316
Cylance Unsafe
VIPRE Trojan.Win32.VBKrypt.abkr (v)
K7AntiVirus Trojan-Downloader ( 001f4fd41 )
BitDefender Trojan.GenericKD.45597316
K7GW Trojan-Downloader ( 001f4fd41 )
Cybereason malicious.74c60a
Baidu Win32.Worm.VB.al
Cyren W32/Vobfus.L.gen!Eldorado
Symantec W32.Changeup
TotalDefense Win32/Vobfus.MQ
APEX Malicious
ClamAV Win.Trojan.VB-1549
Kaspersky Worm.Win32.VBNA.brqy
NANO-Antivirus Trojan.Win32.VBKrypt.dzolqd
ViRobot Worm.Win32.A.VBNA.143360.AAR
Ad-Aware Trojan.GenericKD.45597316
Sophos ML/PE-A + Mal/SillyFDC-I
Comodo Worm.Win32.VB.ww@2ajsup
F-Secure Worm:W32/Vobfus.AX
BitDefenderTheta AI:Packer.18C6153120
TrendMicro WORM_VOBFUS.SMIC
Emsisoft Trojan.GenericKD.45597316 (B)
SentinelOne Static AI – Malicious PE – Worm
Jiangmin Worm/VBNA.gxny
Avira TR/Otran.AA
Antiy-AVL Worm/Win32.WBNA.gen
Arcabit Trojan.Generic.D2B7C284
SUPERAntiSpyware Trojan.Agent/Gen-FakeAlert
ZoneAlarm Worm.Win32.VBNA.brqy
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Jorik.R1884
Acronis suspicious
McAfee Downloader-CJX.gen.l
TACHYON Worm/W32.VB-VBNA.143360
VBA32 SScope.Trojan.VBRA.5166
Malwarebytes Vobfus.Worm.Evasion.DDS
TrendMicro-HouseCall WORM_VOBFUS.SMIC
Yandex Trojan.GenAsa!DJXzsFP6hFw
MAX malware (ai score=80)
eGambit Unsafe.AI_Score_99%
Fortinet W32/AutoRun.XM!worm
Panda W32/Vobfus.FL
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM03.0.09F7.Malware.Gen

How to remove Worm.Win32.VBNA.brqy?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.2988467486 (file analysis)

The Malware.AI.2988467486 is considered dangerous by lots of security experts. When this infection is active,…

40 seconds ago

What is “Malware.AI.3626822667”?

The Malware.AI.3626822667 is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Trojan:Win32/Zusy.GXZ!MTB information

The Trojan:Win32/Zusy.GXZ!MTB is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

Malware.AI.1681308215 removal tips

The Malware.AI.1681308215 is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

Application.Babar.402455 removal tips

The Application.Babar.402455 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Malware.AI.4231428423 removal

The Malware.AI.4231428423 is considered dangerous by lots of security experts. When this infection is active,…

43 mins ago