Trojan

Trojan.Win32.Vobfus.kfd (file analysis)

Malware Removal

The Trojan.Win32.Vobfus.kfd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vobfus.kfd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Vobfus.kfd?


File Info:

name: C4A0902B77D8F1C33E65.mlw
path: /opt/CAPEv2/storage/binaries/9ec42c1e135ad805247ede60ad4073cd1740f54470dc4a70f36e01be4a0ce649
crc32: 6AD93123
md5: c4a0902b77d8f1c33e65f732911199b4
sha1: 69b29d723a479111607a225270a70fe8d4c314c7
sha256: 9ec42c1e135ad805247ede60ad4073cd1740f54470dc4a70f36e01be4a0ce649
sha512: d832f07419f40c8c8fd8c51ecb064fc427d903d3e2ba74a42ae5d3d3d83ff0fb8e700f39d26401f0bf520cf92d78092cf7272aba25bac6dee57ac1550680485e
ssdeep: 1536:daMPl02OnFyJii6Hf8O6j6/t66366Z6Jz36s6eA66KD6sqG/Oj9h6FA8HxAH6xMK:U92OnF2SkAz0+MZZZZWMkIJkI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127C36053E7801072E69A613DA7D2CAB335BEF428CD7A94CA992421EC4CF9D7010EE753
sha3_384: ca20ad4e10b264653b42fb60c1231ff5eccfe185b90011ac9f79ae8feae3caab4da09bdf71a2ea9af895580b19f751a5
ep_bytes: 68e8124000e8eeffffff000000000000
timestamp: 2000-01-24 11:01:17

Version Info:

Translation: 0x0409 0x04b0
Comments: bootnebgibvbsk
CompanyName: eyobxor
FileDescription: slmkhfbosxv
LegalCopyright: uddbujatfyuk
LegalTrademarks: gfxwztzq
ProductName: xukqrabnfc
FileVersion: 5.01.0002
ProductVersion: 5.01.0002
InternalName: ayheatzl
OriginalFilename: ayheatzl.exe

Trojan.Win32.Vobfus.kfd also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
FireEyeGeneric.mg.c4a0902b77d8f1c3
CAT-QuickHealW32.Virut.G
ALYacTrojan.GenericKDZ.96141
Cylanceunsafe
ZillyaTrojan.Vobfus.Win32.617958
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.f2ec
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.b77d8f
BaiduWin32.Worm.VB.ai
VirITTrojan.Win32.X-Cryptor.GDM
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AWE
APEXMalicious
ClamAVWin.Trojan.VB-1629
KasperskyTrojan.Win32.Vobfus.kfd
BitDefenderTrojan.GenericKDZ.96141
NANO-AntivirusTrojan.Win32.Vobfus.chzvil
ViRobotTrojan.Win32.A.Vobfus.131072.P
MicroWorld-eScanTrojan.GenericKDZ.96141
AvastWin32:VB-ADBB [Trj]
TencentTrojan.Win32.Vobfus.haq
TACHYONTrojan/W32.Agent.126976
EmsisoftTrojan.GenericKDZ.96141 (B)
F-SecureTrojan.TR/Jorik.Vobfus.ec.j
DrWebWin32.HLLW.Autoruner1.16354
VIPRETrojan.GenericKDZ.96141
TrendMicroMal_Vbfus-3
McAfee-GW-EditionBehavesLike.Win32.Autorun.cm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-AC
IkarusTrojan.Patched
GDataTrojan.GenericKDZ.96141
JiangminTrojan/Vobfus.sqy
AviraTR/Jorik.Vobfus.ec.j
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Generic.D1778D
SUPERAntiSpywareTrojan.Agent/Gen-Autogen
ZoneAlarmTrojan.Win32.Vobfus.kfd
MicrosoftWorm:Win32/Vobfus.FH
GoogleDetected
AhnLab-V3Worm/Win32.Vobfus.R55533
McAfeeVBObfus.ek
MAXmalware (ai score=84)
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaGeneric Malware
RisingWorm.Win32.FakeFolder.bk (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Jorik.EGLG!tr
BitDefenderThetaGen:NN.ZevbaF.36196.hu0@aaMwATni
AVGWin32:VB-ADBB [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Vobfus.kfd?

Trojan.Win32.Vobfus.kfd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment