Malware

W32/Vobfus-P information

Malware Removal

The W32/Vobfus-P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Vobfus-P virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine W32/Vobfus-P?


File Info:

name: C5121AECB758413F0BB1.mlw
path: /opt/CAPEv2/storage/binaries/5544dfb1f7562bd9d3b5fbe5892f09da83fd86339cf606899503a9cf9403aada
crc32: AC1110CB
md5: c5121aecb758413f0bb14f57d9bd8f57
sha1: 5ed3e31e71f4d8c71f0a3d83da79a768de8f329a
sha256: 5544dfb1f7562bd9d3b5fbe5892f09da83fd86339cf606899503a9cf9403aada
sha512: e085f0d4217389917d7223a1737eb3bf404b928991d3ec7c11f26bd3a413828bd938cf5b0fceb12be9cee697a5a03de13b4a95383e1ec0ac0597b384def76962
ssdeep: 3072:DmRiCR8RT+i5/vwOV/FB671omXB1Gt87e:DmR0RT+i5rYo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187D3A42E7790F67EC425C6F43D1A43A0907AAD3521D2AD03F7C61B1AB6F1EA79220747
sha3_384: 84178f1a15f68f2ada322b0b71ba73ad08134286e9e4c6712a29ecee7217283b309b6ca5e6503f14ef970b1c2f77c604
ep_bytes: 68c8384000e8f0ffffff000000000000
timestamp: 2011-07-27 00:54:59

Version Info:

Translation: 0x0409 0x04b0
ProductName: ebahjxMAAIebGcZkYBXK
FileVersion: 1.00
ProductVersion: 1.00
InternalName: FuHZByOsESxi
OriginalFilename: FuHZByOsESxi.exe

W32/Vobfus-P also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.1b!c
MicroWorld-eScanGen:Variant.VBKrypt.55
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.c5121aecb758413f
CAT-QuickHealTrojan.Vobfus.gen
ALYacGen:Variant.VBKrypt.55
Cylanceunsafe
ZillyaTrojan.Inject.Win32.335342
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ff14.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.cb7584
BaiduWin32.Worm.VB.lk
VirITWorm.Win32.Generic.AVYA
CyrenW32/Vobfus.W.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AIY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.bgnn
BitDefenderGen:Variant.VBKrypt.55
NANO-AntivirusTrojan.Win32.Inject.dxqgeq
AvastWin32:VB-WVF [Trj]
TencentTrojan.Win32.Inject.km
TACHYONTrojan/W32.VB-Inject.135168.O
SophosW32/Vobfus-P
F-SecureWorm.WORM/Vobfus.dazrc
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.VBKrypt.55
TrendMicroMal_VBNA-7
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
EmsisoftGen:Variant.VBKrypt.55 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.VBKrypt.55
AviraWORM/Vobfus.dazrc
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Vobfus.DG@5q5mo0
ArcabitTrojan.VBKrypt.55
ZoneAlarmTrojan.Win32.Inject.bgnn
MicrosoftWorm:Win32/Vobfus.DA
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R19677
McAfeeVBObfus.g
MAXmalware (ai score=89)
VBA32BScope.Worm.VBNA
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_VBNA-7
RisingWorm.VobfusEx!1.99E0 (CLASSIC)
YandexTrojan.GenAsa!XVzgbND7dao
IkarusWorm.Gamarue
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.CNE!worm
BitDefenderThetaAI:Packer.D62E527720
AVGWin32:VB-WVF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove W32/Vobfus-P?

W32/Vobfus-P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment