Worm

About “Worm.VobfusoVMF.S28413072” infection

Malware Removal

The Worm.VobfusoVMF.S28413072 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.VobfusoVMF.S28413072 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.VobfusoVMF.S28413072?


File Info:

name: F25205B978FBDE172623.mlw
path: /opt/CAPEv2/storage/binaries/eddcc67360a19fe68ab70dbebc750d1928ba6b9300c41d9936f01c6d559e2550
crc32: 961E1FA4
md5: f25205b978fbde17262322a41dc1d1b8
sha1: 651416d62ab3c8addfc3862c32f84298c12ccb3f
sha256: eddcc67360a19fe68ab70dbebc750d1928ba6b9300c41d9936f01c6d559e2550
sha512: 3d5db7bb62ea46abebd9c4c91fc4bf5f4d2873aeb14f21eb7f0c8a02ada4bb521202c347b3afd89d6f52080363cedbfe9cd01392335b7cb1414b8b402dffb2bd
ssdeep: 6144:W04PfpHlp1KKcwjIDaTObcZ/pHkMK/fObT/bGiCV/COqoS5Buidx:W04npFp1jaaTObcZ/pHkMK/fObT/bGiz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12734A566BB00E02EE40298F16A2C8A9A78685D3637D0FC5777825F187AB25D374F071F
sha3_384: f4b0ec251b4d4cf6559503265c071c18501b592d9d4b3228b6b80eedc2ceba5ccc5fddcc9ef6d4e15e29fec0c6919b66
ep_bytes: 6814394000e8eeffffff000000000000
timestamp: 2011-10-16 15:14:11

Version Info:

t: q

Worm.VobfusoVMF.S28413072 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lw12
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.60
MicroWorld-eScanGen:Variant.VBKrypt.23
FireEyeGeneric.mg.f25205b978fbde17
CAT-QuickHealWorm.VobfusoVMF.S28413072
SkyhighBehavesLike.Win32.VBObfus.dt
McAfeeVBObfus.l
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.4b909b2b
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.BD3FC9A620
VirITTrojan.Win32.Generic.AFTR
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ANV
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.Vobfus.cqkxoa
SUPERAntiSpywareTrojan.Agent/Gen-Vban
EmsisoftGen:Variant.VBKrypt.23 (B)
F-SecureTrojan.TR/Vobfus.18022544
BaiduWin32.Worm.Autorun.l
VIPREGen:Variant.VBKrypt.23
TrendMicroWORM_VOBFUS.SMJA
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
JiangminWorm.Vobfus.qzfr
VaristW32/Vobfus.AA.gen!Eldorado
AviraTR/Vobfus.18022544
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.AutoRun.AMH@4owee9
ArcabitTrojan.VBKrypt.23
ZoneAlarmWorm.Win32.Vobfus.dgny
MicrosoftWorm:Win32/Vobfus.gen!O
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R14524
Acronissuspicious
VBA32BScope.Worm.Vobfus
ALYacGen:Variant.VBKrypt.23
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallWORM_VOBFUS.SMJA
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!u4ZEr+UfcrQ
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Diple.chca
FortinetW32/Diple.ZMH2!tr
PandaW32/Vobfus.GEW.worm
alibabacloudWorm:Win/Vobfus.1c75c314

How to remove Worm.VobfusoVMF.S28413072?

Worm.VobfusoVMF.S28413072 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment