Worm

Worm.Win32.WBNA.rw removal

Malware Removal

The Worm.Win32.WBNA.rw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.WBNA.rw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.WBNA.rw?


File Info:

name: 9137AAD51AA6C7705693.mlw
path: /opt/CAPEv2/storage/binaries/274aa205e1e71d7930731c638dc765722a686bd28722d50d4304bc0d210596d1
crc32: 8BD51EA8
md5: 9137aad51aa6c77056931c25f417cd4e
sha1: f0e0b3fbb3e2a5c261ef4458446f237a9638ac61
sha256: 274aa205e1e71d7930731c638dc765722a686bd28722d50d4304bc0d210596d1
sha512: d4959f504a21a42510cd8d3b72af81de96343aa6df499147f100c782be4dd574f89c25157f5f85d705afbfb103b3866c2264c72afe1eebf2a73b14ef67f16c39
ssdeep: 6144:q28GpDuIqCHE28LuU4SDOZ+5H88EZeeSzbjnNu91uzqI/:qgDuxamSUDO4HfEZeeSLnA91
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D342044B380A9BBE4B18DF9A785039340946E3859E57313B3C1971A66F9CE6C3707EB
sha3_384: 6d9a9c33537cbdda4d3e95d2b8bd945fa940f31ba5ec8722cf6a31156fd86a88a27238e8cc261718dac6b49da207a97b
ep_bytes: 68f03e4000e8eeffffff000000000000
timestamp: 2011-03-10 03:54:45

Version Info:

Translation: 0x0409 0x04b0
ProductName: BtIEoVCfpbxEtXWwSuWLsrFqL
FileVersion: 9.21
ProductVersion: 9.21
InternalName: WJTOklEfIkV
OriginalFilename: WJTOklEfIkV.exe

Worm.Win32.WBNA.rw also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.llS0
MicroWorld-eScanGen:Variant.VBKrypt.55
FireEyeGeneric.mg.9137aad51aa6c770
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacGen:Variant.VBKrypt.55
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.51aa6c
BitDefenderThetaAI:Packer.452E6FAB21
VirITTrojan.Win32.Zyx.I
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ACE
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMHC
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.rw
BitDefenderGen:Variant.VBKrypt.55
NANO-AntivirusTrojan.Win32.WBNA.eahbev
AvastWin32:VB-RXB [Trj]
TencentWorm.Win32.WBNA.hm
TACHYONTrojan/W32.VB-Agent.233472.CW
EmsisoftGen:Variant.VBKrypt.55 (B)
BaiduWin32.Worm.VB.tn
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.VBKrypt.55
TrendMicroWORM_VOBFUS.SMHC
SophosMal/SillyFDC-M
IkarusWorm.Win32.Vobfus
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Vobfus.P.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Autorun.BAZK@592clb
ArcabitTrojan.VBKrypt.55
ViRobotWorm.Win32.Vobfus.233472
ZoneAlarmWorm.Win32.WBNA.rw
GDataGen:Variant.VBKrypt.55
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C81077
Acronissuspicious
McAfeeVBObfus.g
MAXmalware (ai score=80)
VBA32BScope.Worm.WBNA
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEP
RisingWorm.Vobfus!8.10E (TFE:3:XvV9VMt3ddV)
YandexTrojan.GenAsa!++H30eqdpfY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.CA!tr
AVGWin32:VB-RXB [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.Win32.WBNA.rw?

Worm.Win32.WBNA.rw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment