Worm

Worm.Win32.VBNA.iby removal guide

Malware Removal

The Worm.Win32.VBNA.iby is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VBNA.iby virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.VBNA.iby?


File Info:

name: B7836F67F5EDA6186403.mlw
path: /opt/CAPEv2/storage/binaries/d03b2a14ecd6028d695d4451b9b0935d321645fecebf62e2abbcc5abddea9c3c
crc32: EBE9C302
md5: b7836f67f5eda618640368937b4535e0
sha1: 083350e0d6ce7657c1bc5784989e1d50a4f51bb7
sha256: d03b2a14ecd6028d695d4451b9b0935d321645fecebf62e2abbcc5abddea9c3c
sha512: ff5d418a2354248638494547ede2eb9b7b1fe8ecc90888c67db037a41b5ff82b8697ded7701d553f285d63b996841eb1f96e8b475d0bc8ffb439bd24d377a741
ssdeep: 768:ni/Hd29l2e/AXe04H7cHPHYmcg6UXQm1dIZE2ocOT77e:nn2UpHy96S3T77
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D13C62A77450826DB49733A369BC3CB16A3B0DE1B0F4B476A6A17BCDC24E503D56B07
sha3_384: 6699f4ec1bd18272851675a61415326a90de328828888bbba891ef374bd988e2d63d02c77c035cc967b27c4dabedf2dd
ep_bytes: 684c124000e8f0ffffff000000000000
timestamp: 2000-01-01 00:00:00

Version Info:

0: [No Data]

Worm.Win32.VBNA.iby also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.MulDrop.34673
MicroWorld-eScanGen:Trojan.Chinky.2
FireEyeGeneric.mg.b7836f67f5eda618
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.pt
McAfeeVBObfus
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Trojan.Chinky.2
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.dae1dce6
K7GWEmailWorm ( 00568eab1 )
K7AntiVirusEmailWorm ( 00568eab1 )
BitDefenderThetaAI:Packer.0C53A6D51F
VirITTrojan.Win32.Agent.CWQ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.VB.GG
APEXMalicious
TrendMicro-HouseCallWORM_VB.SMP
ClamAVWin.Trojan.Chinky-2
KasperskyWorm.Win32.VBNA.iby
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.Agent.bkprfp
SUPERAntiSpywareTrojan.Agent/Gen-NameThief
AvastWin32:VB-NIK [Wrm]
TencentWorm.Win32.VBna.g
EmsisoftGen:Trojan.Chinky.2 (B)
F-SecureWorm:W32/Vinkus.gen!A
BaiduWin32.Worm.AutoRun.cj
ZillyaWorm.VBNA.Win32.37043
TrendMicroWORM_VB.SMP
Trapminemalicious.moderate.ml.score
SophosW32/Autorun-ARS
IkarusTrojan.Autorun
JiangminWorm/Vobfus.jmp
GoogleDetected
AviraWORM/VBNA.iby
VaristW32/Vobfus.C.gen!Eldorado
Antiy-AVLWorm/Win32.VBNA.a
KingsoftWin32.Worm.VBNA.iby
MicrosoftWorm:Win32/Vobfus.C
XcitiumWorm.Win32.VBNA.~gen@1qlvkj
ArcabitTrojan.Chinky.2
ViRobotWorm.Win32.A.VBNA.45056.APF
ZoneAlarmWorm.Win32.VBNA.iby
GDataGen:Trojan.Chinky.2
CynetMalicious (score: 100)
AhnLab-V3Win32/Vbna.worm.40960
Acronissuspicious
VBA32SScope.Trojan.VB.Svchorse.026
ALYacGen:Trojan.Chinky.2
TACHYONWorm/W32.VBNA.45056
Cylanceunsafe
PandaW32/Vobfus.gen.worm
RisingTrojan.Autorun!1.DA78 (CLASSIC)
YandexTrojan.GenAsa!Nmq1GgqIrOs
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.849680.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:VB-NIK [Wrm]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/VBNA.iby

How to remove Worm.Win32.VBNA.iby?

Worm.Win32.VBNA.iby removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment