Worm

About “Worm.VobfusMF.S28112626” infection

Malware Removal

The Worm.VobfusMF.S28112626 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.VobfusMF.S28112626 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.VobfusMF.S28112626?


File Info:

name: D533D9A241A9A6AB14B7.mlw
path: /opt/CAPEv2/storage/binaries/0dd004a1cc81569dd7e8e14af6925c5ead3423d2c6ae7f0a333c72908a092e57
crc32: ACAE5424
md5: d533d9a241a9a6ab14b766decc76bf40
sha1: d63a3c19fa5155860e968d8952c1ee33e57cad15
sha256: 0dd004a1cc81569dd7e8e14af6925c5ead3423d2c6ae7f0a333c72908a092e57
sha512: d3a479841a0d17656a5fe5f48ef3943e6492d3fd2c11d75e88fabdaa1b6a2a631b4a058509247b8863a7845e004cbe3a746febc5d1d49da75c7ad29e5e586e94
ssdeep: 3072:9XyqNsMoBuKnBZVpl2mclbj4Uvx+8ysNOu+2eRcKksU61JkkX39RLrw4ySKUbaxG:kqN5gp4LnbmlrZ3X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE24097ABB819689D568193125E2C7F01773780E4F3B818FAA443A2E3C72F344E69757
sha3_384: 77900c71435d012af3465cf4b666f76d0c7aa79858191fd2e70a099bebe5f17b573a34915f9ba51a459dc1340accde83
ep_bytes: 6884154000e8f0ffffff000078000000
timestamp: 1998-10-26 12:06:05

Version Info:

Translation: 0x0409 0x04b0
Comments: lagnanze quinquertium
CompanyName: lagnanze quinquertium
FileDescription: lagnanze quinquertium
LegalCopyright: lagnanze quinquertium
LegalTrademarks: lagnanze quinquertium
ProductName: lagnanze quinquertium
FileVersion: 2.72
ProductVersion: 2.72
InternalName: aiuterebbe
OriginalFilename: aiuterebbe.exe

Worm.VobfusMF.S28112626 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.56765
ClamAVWin.Trojan.VB-1705
CAT-QuickHealWorm.VobfusMF.S28112626
ALYacTrojan.GenericKDZ.56765
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 003c363a1 )
K7AntiVirusEmailWorm ( 003c363a1 )
BaiduWin32.Worm.Pronny.f
VirITTrojan.Win32.Generic.BAVO
CyrenW32/VB.HA.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.CQ
ZonerTrojan.Win32.136135
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dgwx
BitDefenderTrojan.GenericKDZ.56765
NANO-AntivirusTrojan.Win32.Pronny.cazmez
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AEDK [Trj]
TencentWorm.Win32.Vobfus.m
EmsisoftTrojan.GenericKDZ.56765 (B)
F-SecureTrojan.TR/Spy.Agent.229365
DrWebWorm.Siggen.10987
VIPRETrojan.GenericKDZ.56765
TrendMicroWORM_VOBFUS.SMIV
McAfee-GW-EditionBehavesLike.Win32.Autorun.dm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d533d9a241a9a6ab
SophosMal/Kovter-W
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10X5P7O
JiangminTrojan/Generic.arppo
WebrootW32.Dropper.Gen
AviraTR/Spy.Agent.229365
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.cq@4ri78t
ArcabitTrojan.Generic.DDDBD
ViRobotWorm.Win32.A.VBNA.253952.JS
ZoneAlarmWorm.Win32.Vobfus.dgwx
MicrosoftWorm:Win32/Vobfus.GZ
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R43065
Acronissuspicious
McAfeeGenDownloader.rv
TACHYONWorm/W32.Vobfus.229376.C
VBA32Worm.Vobfus
Cylanceunsafe
PandaW32/Vobfus.GEP.worm
TrendMicro-HouseCallWORM_VOBFUS.SMIV
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!iZfPjxcJ+sQ
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
BitDefenderThetaGen:NN.ZevbaF.36318.oq0@aWGXZIpi
AVGWin32:VB-AEDK [Trj]
Cybereasonmalicious.241a9a
DeepInstinctMALICIOUS

How to remove Worm.VobfusMF.S28112626?

Worm.VobfusMF.S28112626 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment