Worm

Worm.VobfusMF.S27266072 malicious file

Malware Removal

The Worm.VobfusMF.S27266072 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.VobfusMF.S27266072 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.VobfusMF.S27266072?


File Info:

name: 9C727FC98AE4C55C1D5F.mlw
path: /opt/CAPEv2/storage/binaries/0e16ac8f2891761407c6d904d061bc6eba35a73f36d26d0e8061bd49195c033f
crc32: EF4DD134
md5: 9c727fc98ae4c55c1d5ff7e340983a2b
sha1: 116831d66e7fe8995226aca4afdad435fb6480dc
sha256: 0e16ac8f2891761407c6d904d061bc6eba35a73f36d26d0e8061bd49195c033f
sha512: b4120864a3315a17bc515f226b25b4047abec07638f0060d03b08bf34d2d6b309c3260f5cb9393cd79af92d57851065b061224848cfa27f82aa88bce3efe9a90
ssdeep: 3072:Ou1zrDOFBTZCchor5KFjvFP5YCkyJnnrr:lN07ha5KFjNcaH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163F3093ABA86899DD759167028E7C7F213B3741A5F07490F3688376A2CB1F342E59B43
sha3_384: 72a801d941410756ea094802608869d881424fd4cfeb28326277fcbdb35155fa8685477ffc4283942fdfb349daa4e38f
ep_bytes: 68d4174000e8f0ffffff000050000000
timestamp: 2012-09-21 17:27:19

Version Info:

Translation: 0x0409 0x04b0
ProductName: radiasti
FileVersion: 4.03
ProductVersion: 4.03
InternalName: wreathe
OriginalFilename: wreathe.exe

Worm.VobfusMF.S27266072 also known as:

BkavW32.AIDetectMalware
CyrenCloudW32/VB.HE.gen!Eldorado
LionicTrojan.Win32.Jorik.lCfW
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.96073
ClamAVWin.Trojan.Pronny-2
FireEyeGeneric.mg.9c727fc98ae4c55c
CAT-QuickHealWorm.VobfusMF.S27266072
ALYacTrojan.GenericKDZ.96073
MalwarebytesPronny.Worm.Spreader.DDS
ZillyaWorm.Vobfus.Win32.1353012
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005640b91 )
AlibabaWorm:Win32/vobfus.1030
K7GWTrojan ( 005640b91 )
Cybereasonmalicious.98ae4c
BaiduWin32.Worm.Pronny.gi
VirITTrojan.Win32.Generic.CELD
CyrenW32/VB.HE.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.EL
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.ela
BitDefenderTrojan.GenericKDZ.96073
NANO-AntivirusTrojan.Win32.Vobfus.eodmcn
ViRobotWorm.Win32.A.Vobfus.172032
AvastWin32:VB-AENM [Trj]
TencentWorm.Win32.Vobfus.q
TACHYONWorm/W32.Vobfus.172032.B
SophosMal/SillyFDC-Y
DrWebTrojan.VbCrypt.81
VIPRETrojan.GenericKDZ.96073
TrendMicroWORM_VOBFUS.SM02
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.96073 (B)
IkarusWorm.Win32.Vobfus
GDataWin32.Trojan.VB.SE
JiangminWorm.Vobfus.bni
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Generic.D17749
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmWorm.Win32.Vobfus.ela
MicrosoftWorm:Win32/Vobfus.IE
GoogleDetected
AhnLab-V3Worm/Win32.Vobfus.R38810
McAfeeVBObfus.dv
MAXmalware (ai score=88)
VBA32Worm.Vobfus
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!AWbSy/YbgE4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4564723.susgen
FortinetW32/Diple.EJQE!tr
BitDefenderThetaGen:NN.ZevbaF.36318.km0@aObeXSfi
AVGWin32:VB-AENM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.VobfusMF.S27266072?

Worm.VobfusMF.S27266072 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment