Worm

How to remove “Worm.Vobfus.J”?

Malware Removal

The Worm.Vobfus.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Vobfus.J virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Vobfus.J?


File Info:

name: D31E4132F5C5DD289149.mlw
path: /opt/CAPEv2/storage/binaries/782180daa49c1e9b86ed05178749891be09496d90975c0ea840f3d3d99e94fde
crc32: D08985BD
md5: d31e4132f5c5dd2891495dfec7efb252
sha1: f2e27e2bf048d7bea31fbac0de8e55091e82e66a
sha256: 782180daa49c1e9b86ed05178749891be09496d90975c0ea840f3d3d99e94fde
sha512: 3ea78b51cb897c541acac2c687192c2d491e474f84926aaa58af1734a4534e01396cadcfde834043d33de3d0e1ac0ef1cde9c072927cc931ddc1d256cf2260fc
ssdeep: 6144:ZszftV4NKAyXuS/WiBWuVklOPce2imvDAPbBW6EWfQkmJyOj4ykpZq:kAwBFVkl6ItD4W6EWfQByOj4ykpZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14994D81663E0FA5AD5218EF12E6B4768883AFC3114D1ED03F6D02F1977A6E47A12731B
sha3_384: 6326c7eb68900f1b3739917e8af4338d0b82390cc4f0bd9c5601247a739da28db7cd91d54ebe33231fbaec2b6601f1dc
ep_bytes: 68d8544000e8eeffffff000000000000
timestamp: 2012-10-20 19:46:45

Version Info:

Translation: 0x0409 0x04b0
Comments: jfnm34bnm3b53465346
LegalCopyright: xcvxcvxcbvcvb
ProductName: r48903w2859348756
FileVersion: 1.01
ProductVersion: 1.01
InternalName: Miglioravi
OriginalFilename: Miglioravi.exe

Worm.Vobfus.J also known as:

BkavW32.Common.C8F129DD
LionicWorm.Win32.WBNA.lCcH
MicroWorld-eScanWorm.Vobfus.J
FireEyeWorm.Vobfus.J
SkyhighBehavesLike.Win32.Generic.gm
ALYacWorm.Vobfus.J
Cylanceunsafe
VIPREWorm.Vobfus.J
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.88262a3c
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Trojan.Inject.n
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.FU
CynetMalicious (score: 99)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packer.VBCrypt-5731517-0
KasperskyWorm.Win32.Vobfus.aifj
BitDefenderWorm.Vobfus.J
NANO-AntivirusTrojan.Win32.Autoruner1.covlqj
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
TencentMalware.Win32.Gencirc.10b1194d
TACHYONWorm/W32.Vobfus.409600
EmsisoftWorm.Vobfus.J (B)
F-SecureWorm.WORM/Vobfus.abruma
DrWebWin32.HLLW.Autoruner1.28574
BitDefenderThetaGen:NN.ZevbaF.36804.zm0@aqXnFhei
TrendMicroWORM_VOBFUS.SMIT
SophosMal/Generic-R
SentinelOneStatic AI – Suspicious PE
JiangminWorm/WBNA.dffe
WebrootW32.Trojan.Gen
VaristW32/VB.HE.gen!Eldorado
AviraWORM/Vobfus.abruma
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.HeurC.KVM007.a
XcitiumWorm.Win32.Pronny.ICOA@4r5x5p
ArcabitWorm.Vobfus.J
ViRobotWorm.Win32.A.Vobfus.409600
ZoneAlarmWorm.Win32.Vobfus.aifj
GDataWorm.Vobfus.J
GoogleDetected
AhnLab-V3Trojan/Win32.Menti.R27300
McAfeeGenDownloader.rv
MAXmalware (ai score=88)
VBA32Malware-Cryptor.VB.gen
MalwarebytesPronny.Worm.Spreader.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIT
RisingTrojan.Ditertag!8.F693 (TFE:3:ddr2ijyWH1V)
YandexTrojan.GenAsa!4nnCyIy0u04
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.11611748.susgen
FortinetW32/VBKrypt.C!tr
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.Vobfus.J?

Worm.Vobfus.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment