Worm

Worm.VobfusVMF.S20098280 removal

Malware Removal

The Worm.VobfusVMF.S20098280 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.VobfusVMF.S20098280 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.VobfusVMF.S20098280?


File Info:

name: F085E16E04FBBFF651BC.mlw
path: /opt/CAPEv2/storage/binaries/7032daf7159eda596b45c9b0f6b0dedaa49647907c07db87332ecbf32ad63185
crc32: 63DD80E0
md5: f085e16e04fbbff651bc910fd0157051
sha1: 99f6574d112a8e193d5e37bf11aa502ab7865799
sha256: 7032daf7159eda596b45c9b0f6b0dedaa49647907c07db87332ecbf32ad63185
sha512: f9e9a5e86c075551a7583c391058f2d583b9ee833aef1542b3a64ba0fbd44bced40310cf3bdc7a5ac63eb727143db398b8e30e69330b5f3f170c77034f33b0fe
ssdeep: 3072:yJSag+CWoYTzCh46Knvmb7/D26ytQlw/Lg5q69srijEgS36:NGpz6LKnvmb7/D26yQlw/Lg5qosriHSK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D204A627BB05B02BE156C8F09E389656353C2E3626D06C4777C47F2966705ABB8B072F
sha3_384: f81c0c6fe9d68816f04799afea2579dca3a725d92552662861b182834c2657db38f2b2d1d81288ca910258aeecfb9c89
ep_bytes: 6848384000e8f0ffffff000000000000
timestamp: 2011-12-05 01:01:08

Version Info:

0: [No Data]

Worm.VobfusVMF.S20098280 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.95599
FireEyeGeneric.mg.f085e16e04fbbff6
CAT-QuickHealWorm.VobfusVMF.S20098280
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacTrojan.GenericKDZ.95599
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e04fbb
BaiduWin32.Worm.Autorun.l
VirITWorm.Win32.Generic.BDWW
SymantecW32.Changeup!gen15
tehtrisGeneric.Malware
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Changeup-6169544-0
BitDefenderTrojan.GenericKDZ.95599
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
SophosMal/SillyFDC-T
GoogleDetected
F-SecureWorm.WORM/Vobfus.ommlc
BitDefenderThetaAI:Packer.13CD86A220
ZillyaWorm.WBNAGen.Win32.21
TrendMicroWORM_VOBFUS.SMAB
EmsisoftTrojan.GenericKDZ.95599 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.AA.gen!Eldorado
AviraWORM/Vobfus.ommlc
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1756F
ViRobotTrojan.Win32.A.Diple.188416.G
GDataTrojan.GenericKDZ.95599
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R16967
Acronissuspicious
McAfeeVBObfus.cd
TACHYONTrojan/W32.VB-Diple.188416
VBA32BScope.Trojan.Diple
Cylanceunsafe
YandexTrojan.GenAsa!XAhSjj6OqvE
MAXmalware (ai score=84)
FortinetW32/VB.ADV!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.38e1a6e4

How to remove Worm.VobfusVMF.S20098280?

Worm.VobfusVMF.S20098280 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment