Worm

Worm.Win32.VBNA.bsmw (file analysis)

Malware Removal

The Worm.Win32.VBNA.bsmw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VBNA.bsmw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.VBNA.bsmw?


File Info:

name: C298BD178CAE50537F9E.mlw
path: /opt/CAPEv2/storage/binaries/e5b07776b4b55dc8ed9eeb91557f179c3c39a0958a59267f9c8b9e1dcda30d18
crc32: A931308F
md5: c298bd178cae50537f9e1b8a4bc8c44d
sha1: 936c10c2e97a0dba12574cb297e62f0ed12b4ac6
sha256: e5b07776b4b55dc8ed9eeb91557f179c3c39a0958a59267f9c8b9e1dcda30d18
sha512: 2638580ca71bd382cddc71f54c7dab1b05e9d4ffee01bf6fdd61d2aaed85448c247f38a6bd3994bbceacaa354d9a4d701dd50fb2ed8bfdb55feca7f43ac46327
ssdeep: 1536:eIAxBe2+DKsZLyJxFdhXgI0TRQP/FY0Y6Y2YkYGYHRHNxtwv4RaoacXcmKdPBa:2eNDDpCH6QP/uRNBcZw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13993712B778010E7C95846B52DC3B7C715B62A851A273A835A203796FC75E020B7E9FF
sha3_384: cc4f0ba3fef181a800c12fd5029784beeb00d4db3d753dc987770c3bbd0cfc9545692dbf807b7eec9deff7e400cb4206
ep_bytes: 68a0124000e8eeffffff000000000000
timestamp: 2011-02-14 09:16:47

Version Info:

Translation: 0x0409 0x04b0
ProductName: VTRmTz
FileVersion: 5.15
ProductVersion: 5.15
InternalName: CmVPni
OriginalFilename: CmVPni.exe

Worm.Win32.VBNA.bsmw also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-RED [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.209946
FireEyeGeneric.mg.c298bd178cae5053
CAT-QuickHealWorm.VobfusMF.S27814427
SkyhighBehavesLike.Win32.VBObfus.nt
McAfeeVBObfus.f
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.Lazy.209946
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
K7GWTrojan-Downloader ( 001ff72a1 )
BaiduWin32.Worm.AutoRun.cj
VirITTrojan.Win32.Generic.ATAM
SymantecW32.Changeup!gen10
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ABA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.VBNA.bsmw
BitDefenderGen:Variant.Lazy.209946
NANO-AntivirusTrojan.Win32.AutoRun.covjyr
AvastWin32:VB-RED [Trj]
TencentWorm.Win32.Vbna.kew
EmsisoftGen:Variant.Lazy.209946 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Packed.21430
TrendMicroWORM_VOBFUS.SMIA
Trapminemalicious.moderate.ml.score
SophosW32/SillyFDC-FT
SentinelOneStatic AI – Malicious PE
JiangminWorm/VBNA.gzmz
VaristW32/VB.BR.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus.BB
XcitiumPacked.Win32.Krap.BV@2qqlmo
ArcabitTrojan.Lazy.D3341A
ViRobotTrojan.Win32.A.VBKrypt.94208.E
ZoneAlarmWorm.Win32.VBNA.bsmw
GDataGen:Variant.Lazy.209946
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R3045
BitDefenderThetaAI:Packer.8D28449720
TACHYONTrojan/W32.VB-Krypt.94208.E
VBA32Trojan.VBRA.010801
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingWorm.VobfusEx!1.99EB (CLASSIC)
IkarusGen.Variant.VBKrypt
FortinetW32/AutoRun.XM!worm
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.Win32.VBNA.bsmw?

Worm.Win32.VBNA.bsmw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment