Worm

Worm.Win32.WBNA.mxu removal instruction

Malware Removal

The Worm.Win32.WBNA.mxu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.WBNA.mxu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.Win32.WBNA.mxu?


File Info:

name: A768E75F44B5FE6FBBE0.mlw
path: /opt/CAPEv2/storage/binaries/ec7a774ee7a84e53e918dc792c47a3b70a8c738f2b7c7136d125e0f51889a531
crc32: 4CCA994B
md5: a768e75f44b5fe6fbbe04cb029e1fd03
sha1: 06295367b548b17039415ced01efb594ba144af4
sha256: ec7a774ee7a84e53e918dc792c47a3b70a8c738f2b7c7136d125e0f51889a531
sha512: 791ebd7936f4bd1c10c17ae38aef2b30166cc8cd4d32aae07c903ce76a1ee684b7024a7689716431c30d46bca0cc56db20ac2cf0cba68ecf14b6b926a957ed7e
ssdeep: 1536:g3eUc4EVT8JNenyIGmvcTlfbfwVocTzFJ0T72Vpcz:jUcxYhTxSBTzFJ0T72Qz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118930E1A77615422F70879723B43C7E339A76C4E9E1F91867744B9DB68A8E080C1DBE3
sha3_384: 8d6c111dfcc32e21891b20756e11ba2eccadaa7b3df4a2ba370d18ab47c9b4b313f7674c24bae5a7c25b1bf982ed7964
ep_bytes: 6824124000e8eeffffff000000000000
timestamp: 2012-06-29 22:39:21

Version Info:

Translation: 0x0409 0x04b0
Comments: Gastric
CompanyName: Gastric
FileDescription: Gastric
LegalCopyright: Gastric
LegalTrademarks: Gastric
ProductName: Gastric
FileVersion: 8.44
ProductVersion: 8.44
InternalName: Portless
OriginalFilename: Portless.exe

Worm.Win32.WBNA.mxu also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lwz0
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.VB.Agent.3
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.a768e75f44b5fe6f
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Heur.VB.Agent.3
Cylanceunsafe
ZillyaWorm.WBNA.Win32.1545033
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_27b2.None
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.VB.Agent.3
VirITWorm.Win32.X-Autorun.BBDH
CyrenW32/Vobfus.AT.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Pronny.BF
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.mxu
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.WBNA.cqkxzw
AvastWin32:VB-ADNO [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.WBNA.94208.B
SophosMal/SillyFDC-Y
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.18337
VIPREGen:Heur.VB.Agent.3
TrendMicroWORM_WBNA.SMD
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nm
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.VB.Agent.3 (B)
IkarusTrojan.Crypt
JiangminTrojan/Vbobf.b
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
MicrosoftWorm:Win32/Vobfus.gen!W
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmWorm.Win32.WBNA.mxu
GDataGen:Heur.VB.Agent.3
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R48451
McAfeeVBObfus.n
MAXmalware (ai score=86)
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_WBNA.SMD
RisingWorm.VobfusEx!1.99E2 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4205716.susgen
FortinetW32/VBObfus.C!tr
BitDefenderThetaGen:NN.ZevbaF.36250.fm0@aaCXSFki
AVGWin32:VB-ADNO [Trj]
DeepInstinctMALICIOUS

How to remove Worm.Win32.WBNA.mxu?

Worm.Win32.WBNA.mxu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment