Worm

Worm.Win32.VBNA.iby (file analysis)

Malware Removal

The Worm.Win32.VBNA.iby is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.VBNA.iby virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.VBNA.iby?


File Info:

name: BC2EB0731AB68F62D389.mlw
path: /opt/CAPEv2/storage/binaries/02d3a04cbb884a8006fe13cb822b9033bac692a6f6409f0b873ccaf11e89c454
crc32: F76FA8B6
md5: bc2eb0731ab68f62d3894570fb1c82be
sha1: c97eda4ef4305988b364b6f0e1951be32ba70c58
sha256: 02d3a04cbb884a8006fe13cb822b9033bac692a6f6409f0b873ccaf11e89c454
sha512: 195076c1f62db573f7e48a2519aa8ba1f1bc70e96faa84d670345f6aa04908c726bfd2af140543546912b9dd299687c4cac38caab8717e3f6faa4d09c8c91bad
ssdeep: 768:AR/Hdu9ZlXaubXe04H7cHPHYmug6UXQm1dIZE2ocOT77e:AoQuSHyj6S3T77
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12BD3C72A77450826EB49733A36ABC3CB16A370DE1B0F4B476A1A17BCEC24E503D56717
sha3_384: d85b492c784736a418fdf3ea9398caf35bb4f74d85cdef2ec7991d9344e6fcb2fd4c4a394e6c7594b9c40be3bac9fad6
ep_bytes: 684c124000e8f0ffffff000000000000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Worm.Win32.VBNA.iby also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.VB.Chinky.K
FireEyeGeneric.mg.bc2eb0731ab68f62
CAT-QuickHealTrojan.Vobfus.gen
SkyhighVBObfus
McAfeeVBObfus
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.VB.Chinky.K
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 00568eab1 )
BitDefenderTrojan.VB.Chinky.K
K7GWEmailWorm ( 00568eab1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36744.imW@aSAPGXb
VirITTrojan.Win32.Agent.CWQ
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.GE
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.VBNA.iby
AlibabaWorm:Win32/vobfus.dd94
NANO-AntivirusTrojan.Win32.Agent.bkprfp
ViRobotWorm.Win32.VBNA.45056.ACQ
TencentWorm.Win32.VBna.g
TACHYONWorm/W32.Vobfus.131072.B
SophosW32/Autorun-ARS
BaiduWin32.Worm.AutoRun.cj
F-SecureWorm:W32/Vinkus.gen!A
DrWebTrojan.MulDrop.34673
ZillyaWorm.VBNA.Win32.37043
TrendMicroWORM_VB.SMP
Trapminemalicious.high.ml.score
EmsisoftTrojan.VB.Chinky.K (B)
IkarusWorm.Win32.VBNA
JiangminWorm.VBNA.bqm
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraWORM/VBNA.iby
Antiy-AVLWorm/Win32.VBNA.a
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.C
XcitiumWorm.Win32.VBNA.~gen@1qlvkj
ArcabitTrojan.VB.Chinky.K
SUPERAntiSpywareTrojan.Agent/Gen-Vbkryp
ZoneAlarmWorm.Win32.VBNA.iby
GDataTrojan.VB.Chinky.K
VaristW32/Vobfus.D.gen!Eldorado
AhnLab-V3Win32/Vbna.worm.40960
Acronissuspicious
VBA32SScope.Trojan.VB.Svchorse.026
ALYacTrojan.VB.Chinky.K
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaW32/Vobfus.gen.worm
TrendMicro-HouseCallWORM_VB.SMP
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:VB-NIK [Wrm]
Cybereasonmalicious.ef4305
AvastWin32:VB-NIK [Wrm]

How to remove Worm.Win32.VBNA.iby?

Worm.Win32.VBNA.iby removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment