Worm

What is “Vobfus.Worm.Evasion.DDS”?

Malware Removal

The Vobfus.Worm.Evasion.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Vobfus.Worm.Evasion.DDS virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Vobfus.Worm.Evasion.DDS?


File Info:

crc32: D21C2270
md5: 9b53f7715642827dfc37180c3b15aab1
name: 9B53F7715642827DFC37180C3B15AAB1.mlw
sha1: b35185f195a2e1291fbe8dee3e79d5bb09983a43
sha256: f834679ecb8119507701b70844e069ccbafc72f63eb069194586c66647086c9c
sha512: 26a3409b9da3999a6105bf6381c74dba5a7c65d315057719325a088f33949a6bf1ec6d4358117a46b3a14ca201a59a70b702d0518641f4f09827c99494dd997f
ssdeep: 6144:dSmrTmHKmlEwrPmRPWEpWFn2E6lyDntvhhOU35RJEesNjA3wU7Hu:dS/qTwr03pdf8vhhOKJEThAB
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Vobfus.Worm.Evasion.DDS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45632119
FireEyeGeneric.mg.9b53f7715642827d
Qihoo-360Win32/Backdoor.QakBot.HycB4yoA
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.45632119
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Qbot.CV
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
Ad-AwareTrojan.GenericKD.45632119
SophosML/PE-A + Mal/EncPk-APW
F-SecureTrojan.TR/AD.Qbot.rssjs
DrWebTrojan.Inject4.6765
McAfee-GW-EditionArtemis!Trojan
EmsisoftMalCert.A (A)
IkarusTrojan.Win32.Hiloti
AviraTR/AD.Qbot.rssjs
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2B84A77
AhnLab-V3Trojan/Win32.QBot.C4311830
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKD.45632119
CynetMalicious (score: 100)
McAfeeArtemis!9B53F7715642
VBA32Backdoor.Qbot
MalwarebytesVobfus.Worm.Evasion.DDS
FortinetW32/Qbot.568!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Vobfus.Worm.Evasion.DDS?

Vobfus.Worm.Evasion.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment