Worm

Worm.VobfusMF.S18680777 (file analysis)

Malware Removal

The Worm.VobfusMF.S18680777 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.VobfusMF.S18680777 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.VobfusMF.S18680777?


File Info:

name: 95ED89D9FEB63AA1EF7D.mlw
path: /opt/CAPEv2/storage/binaries/6b2bacb1f3eddfb0341818303b694599b314649cf50a00ddbfd7430fc3a411a4
crc32: 50734875
md5: 95ed89d9feb63aa1ef7dd360e62fa0d3
sha1: 56b1bfdf8dc709fe10a00c0eaf5a6f006408acd1
sha256: 6b2bacb1f3eddfb0341818303b694599b314649cf50a00ddbfd7430fc3a411a4
sha512: 5a77beb3f74e8357d38c6543f00d2ce279c1513bfef7512203b723a4752d47435b90ee81cfb08b3f585c3d3875ae4974a33f097dc613227419a2cf89d74db320
ssdeep: 3072:mmev95YkQqHd0/sQPO1ouf8Dr//GeTb3O/ea6LOsDxB:25Ykt90/sQx///3Oj6LOs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13964D5677F53655DEC6840313FFE92F12363A4CD8B138506166022E87EFBEA62D5824B
sha3_384: 8fef96eba119bab5a212b2b4f2965c46151236ed8a32b0038ff45dd8871781a128573a597865f38806c117d578b338e2
ep_bytes: 6814134000e8f0ffffff000000000000
timestamp: 2012-05-14 01:52:08

Version Info:

Translation: 0x0409 0x04b0
ProductName: vyhgdptfcfru
FileVersion: 2.07.0005
ProductVersion: 2.07.0005
InternalName: iicysgotsksy
OriginalFilename: iicysgotsksy.exe

Worm.VobfusMF.S18680777 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.2490
FireEyeGeneric.mg.95ed89d9feb63aa1
CAT-QuickHealWorm.VobfusMF.S18680777
SkyhighBehavesLike.Win32.VBObfus.fh
McAfeeVBObfus.dv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.VB.pz
VirITTrojan.Win32.Zyx.KQ
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.AR
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.dgbw
BitDefenderGen:Variant.Barys.2490
NANO-AntivirusTrojan.Win32.Jorik.covlqw
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:Pronny-J [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Barys.2490 (B)
F-SecureTrojan.TR/Jorik.dgbwya
DrWebWin32.HLLW.Autoruner1.33553
VIPREGen:Variant.Barys.2490
TrendMicroWORM_VOBFUS.SM01
Trapminemalicious.high.ml.score
SophosW32/Vobfus-AH
IkarusWorm.Win32.Vobfus
JiangminTrojan/Jorik.gqej
GoogleDetected
AviraTR/Jorik.dgbwya
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.994
MicrosoftWorm:Win32/Vobfus.FD
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.D9BA
ZoneAlarmTrojan.Win32.Jorik.Vobfus.dgbw
GDataWin32.Trojan.PSE.10T9JN3
VaristW32/Vobfus.O.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R24837
BitDefenderThetaGen:NN.ZevbaF.36804.tm0@a0CNpdai
ALYacGen:Variant.Barys.2490
MAXmalware (ai score=81)
VBA32Trojan.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.Pronny!1.AE42 (CLASSIC)
YandexTrojan.GenAsa!r3ZospqUnfU
TACHYONTrojan/W32.Jorik.323584
FortinetW32/Jorik.EGLG!tr
AVGWin32:Pronny-J [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.3dc65197

How to remove Worm.VobfusMF.S18680777?

Worm.VobfusMF.S18680777 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment