Worm

Worm.Win32.WBNA.dn (file analysis)

Malware Removal

The Worm.Win32.WBNA.dn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.WBNA.dn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.WBNA.dn?


File Info:

name: 98DE043A4EFAF6450F8F.mlw
path: /opt/CAPEv2/storage/binaries/f7bf11b350b98cda94c4639fdd404767dfcd030e25624049437f455b0696056d
crc32: B69E2D0A
md5: 98de043a4efaf6450f8f9d111e022a99
sha1: bc6d7e006d61c30e4d926904c6ebcaba2b372a5c
sha256: f7bf11b350b98cda94c4639fdd404767dfcd030e25624049437f455b0696056d
sha512: 5ca9e767604c03c9cb67a304b599c994421152f1d07e7e2679611ffea49982ba55c732173e26c473ffddc1013741804ffb9ce85368eff03c040d877b26cb3aed
ssdeep: 12288:R3dbKqaLgEPQlK4xknviPEZ01LAXR5uK9s8nTUb/o83p/iEYONFn8t:R3dGqaLgEPQXs9s8nTUb/o83waFn8t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B946641B520A637E052E9B2BA55C39B12213D7756A0AC23B7CA4F0751F03E77AF0B5B
sha3_384: f011d378aa947263252d6862d3daa80f8129a70728c62828b326b1ab2a34855c994810ece4e0919cc40dd9e509dafd75
ep_bytes: 68c85f4000e8f0ffffff000000000000
timestamp: 2011-03-30 04:43:45

Version Info:

Translation: 0x0409 0x04b0
ProductName: CUQajGjGjJsaitSJvJWkfRhWYQE
FileVersion: 1.00
ProductVersion: 1.00
InternalName: KihfPiRhwc
OriginalFilename: KihfPiRhwc.exe

Worm.Win32.WBNA.dn also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.55
FireEyeGeneric.mg.98de043a4efaf645
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.gm
McAfeeVBObfus.n
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.a4efaf
BitDefenderThetaAI:Packer.ABD5D76321
VirITTrojan.Win32.SHeur3.BSUQ
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.ADC
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.dn
BitDefenderGen:Variant.VBKrypt.55
NANO-AntivirusTrojan.Win32.WBNA.fcklnt
TencentWorm.Win32.Wbna.kl
EmsisoftGen:Variant.VBKrypt.55 (B)
F-SecureTrojan:W32/Injector.F
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.VBKrypt.55
TrendMicroWORM_VOBFUS.SMHB
SophosMal/SillyFDC-M
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.VBKrypt.55
ViRobotWorm.Win32.A.WBNA.430080
ZoneAlarmWorm.Win32.WBNA.dn
GDataGen:Variant.VBKrypt.55
VaristW32/Vobfus.P.gen!Eldorado
AhnLab-V3Worm/Win32.WBNA.R7742
VBA32BScope.Worm.WBNA
ALYacGen:Variant.VBKrypt.55
TACHYONWorm/W32.VB-WBNA.430080
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallWORM_VOBFUS.SMHB
RisingWorm.Autorun!8.50 (TFE:3:cqaCM0w4OoI)
YandexTrojan.GenAsa!tVxFU53dstc
IkarusTrojan.Win32.VBKrypt
FortinetW32/Generic.AP.11888FE!tr
PandaW32/Vobfus.GEP
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.Win32.WBNA.dn?

Worm.Win32.WBNA.dn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment